Security: flavorjones/loofah
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
SVG `href` attribute bypasses local-reference restriction in LoofahGHSA-9wjq-cp2p-hrgf published
Jul 15, 2026 by flavorjonesModerate -
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolonsGHSA-5qhf-9phg-95m2 published
Jul 15, 2026 by flavorjonesLow -
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character referencesGHSA-8whx-365g-h9vv published
Jul 15, 2026 by flavorjonesLow -
Improper detection of disallowed URIs by Loofah `allowed_uri?`GHSA-46fp-8f5p-pf2m published
Mar 17, 2026 by flavorjonesLow -
Improper neutralization of data URIs may allow XSS in LoofahGHSA-228g-948r-83gx published
Dec 13, 2022 by flavorjonesModerate -
Uncontrolled Recursion in LoofahGHSA-3x8r-x6xp-q4vm published
Dec 13, 2022 by flavorjonesHigh -
Inefficient Regular Expression Complexity in LoofahGHSA-486f-hjj9-9vhh published
Dec 13, 2022 by flavorjonesHigh