loofah
Ruby library for HTML/XML transformation and sanitization
Activity
- Latest release
- 2mo ago
- Total releases
- 65
- Cadence
- ~2 months
- Last 12 months
- 3
Reach
- Stars
- 1.0k
Details
- License
- MIT
- First release
- Aug 11, 2009
| Version | Released | |
|---|---|---|
2.25.2
patch
| ||
2.25.1
patch
3 CVEs
CVE-2026-73492
GHSA-5qhf-9phg-95m2
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
Network
High
Low
None
Summary
This is a bypass of the fix for GHSA-46fp-8f5p-pf2m, which handled numeric character references with a trailing Details
A browser, however, decodes numeric character references even without a trailing semicolon. An encoded colon such as Note that Loofah's default ImpactCallers that validate a user-controlled URL with MitigationUpgrade to Loofah >= 2.25.2. CreditResponsibly reported by GitHub user @MoonFuji. Affected versions
2.25.0
2.25.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73491
GHSA-8whx-365g-h9vv
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
Network
High
Low
None
Summary
This is a bypass of the fix for GHSA-46fp-8f5p-pf2m, which handled the equivalent numeric character references ( Details
Note that Loofah's default ImpactCallers that validate a user-controlled URL with MitigationUpgrade to Loofah >= 2.25.2. CreditResponsibly reported by GitHub user @connorshea. Affected versions
2.25.0
2.25.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.25.0
minor
5 CVEs
CVE-2026-73492
GHSA-5qhf-9phg-95m2
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
Network
High
Low
None
Summary
This is a bypass of the fix for GHSA-46fp-8f5p-pf2m, which handled numeric character references with a trailing Details
A browser, however, decodes numeric character references even without a trailing semicolon. An encoded colon such as Note that Loofah's default ImpactCallers that validate a user-controlled URL with MitigationUpgrade to Loofah >= 2.25.2. CreditResponsibly reported by GitHub user @MoonFuji. Affected versions
2.25.0
2.25.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73491
GHSA-8whx-365g-h9vv
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
Network
High
Low
None
Summary
This is a bypass of the fix for GHSA-46fp-8f5p-pf2m, which handled the equivalent numeric character references ( Details
Note that Loofah's default ImpactCallers that validate a user-controlled URL with MitigationUpgrade to Loofah >= 2.25.2. CreditResponsibly reported by GitHub user @connorshea. Affected versions
2.25.0
2.25.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-2j22-pr5w-6gq8
Mar 26, 2026
Loofah has improper detection of disallowed URIs via `allowed_uri?`
Low
Network
Low
None
Summary
DetailsThe Note that the Loofah sanitizer's default ImpactApplications that call This only affects Loofah MitigationUpgrade to Loofah >= CreditResponsibly reported by HackOne user @smlee. Affected versions
2.25.0
Fixed in
2.25.1
References
Updated Sep 10, 2026 · Source: OSV.dev
GHSA-46fp-8f5p-pf2m
Mar 18, 2026
Improper detection of disallowed URIs by Loofah `allowed_uri?`
Low
Network
Low
None
None
Summary
DetailsThe Note that the Loofah sanitizer's default ImpactApplications that call This only affects Loofah MitigationUpgrade to Loofah >= CreditResponsibly reported by HackOne user Affected versions
2.25.0
Fixed in
2.25.1
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.24.1
patch
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.24.0
minor
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.23.1
patch
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.23.0
minor
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.22.0
minor
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.21.4
patch
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.21.3
patch
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.21.2
patch
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.21.1
patch
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.21.0
minor
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.21.0.rc1
pre
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.20.0
minor
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev |
2.20.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.19.1
patch
1 CVE
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev |
2.19.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.19.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.19.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.18.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.18.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.17.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.17.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.16.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.16.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.15.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.15.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.14.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.14.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.13.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.13.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.12.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.12.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.11.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.11.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
2.10.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.10.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.9.1
patch
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.9.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.9.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.9.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.8.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.8.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.7.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.7.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.6.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.6.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.5.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.5.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.4.0
minor
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.4.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.3.1
patch
4 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev |
2.3.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.3.0
minor
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.2.3
patch
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.2.3
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.2.2
patch
6 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev |
2.2.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.2.1
patch
6 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev |
2.2.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.2.0
minor
7 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23516
GHSA-3x8r-x6xp-q4vm
Dec 13, 2022
Uncontrolled Recursion in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah Users who are unable to upgrade may be able to mitigate this vulnerability by limiting the length of the strings that are sanitized. SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). ReferencesAffected versions
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
+ 11 more Show less
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.2.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.1.1
patch
6 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.1.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.1.0
minor
6 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23515
GHSA-228g-948r-83gx
Dec 13, 2022
Improper neutralization of data URIs may allow XSS in Loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as Medium Severity 6.1. References
CreditThis vulnerability was responsibly reported by Maciej Piechota (@haqpl). Affected versions
2.1.0
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
+ 13 more Show less
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.1.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.1.0.rc2
pre
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.1.0.rc2
pre
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.3
patch
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.0.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.1.0.rc1
pre
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.1.0.rc1
pre
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.2
patch
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.0.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.0.1
patch
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.0.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.0.0
major
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |
2.0.0
major
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
1.2.1
patch
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
1.2.0
minor
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev | ||
1.1.0
minor
5 CVEs
CVE-2026-73490
GHSA-9wjq-cp2p-hrgf
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
SummaryLoofah's HTML5 sanitizer restricted only the ImpactSVG Applications that sanitize user-supplied SVG (directly, or as part of HTML) with Loofah's default allowlist are affected. MitigationUpgrade to Loofah >= 2.25.2. CreditFound by the maintainer, Mike Dalessio, during a security audit. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 52 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.19.1
2.2.0
2.2.1
2.2.2
2.2.3
2.20.0
2.21.0
2.21.0.rc1
2.21.1
2.21.2
2.21.3
2.21.4
2.22.0
2.23.0
2.23.1
2.24.0
2.24.1
2.25.0
2.25.1
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.25.2
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-23514
GHSA-486f-hjj9-9vhh
Dec 13, 2022
Inefficient Regular Expression Complexity in Loofah
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
SummaryLoofah MitigationUpgrade to Loofah SeverityThe Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1). References
CreditThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q). Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 37 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
Fixed in
2.19.1
References
Updated Nov 04, 2025 · Source: OSV.dev
CVE-2019-15587
GHSA-c3gv-9cxf-6f57
Nov 05, 2019
Loofah Allows Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby through v2.3.0, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 19 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
Fixed in
2.3.1
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-16468
GHSA-g4xq-jx4w-4cjv
Nov 01, 2018
Loofah Cross-site Scripting vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
In the Loofah gem for Ruby, through version 2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. Users are advised to upgrade to version 2.2.3. See https://github.com/flavorjones/loofah/issues/154 for more details. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 17 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
2.2.1
2.2.2
Fixed in
2.2.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8048
GHSA-x7rv-cr6v-4vm4
Mar 21, 2018
Cross-site Scripting in loofah
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected. Affected versions
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
+ 15 more Show less
0.4.7
1.0.0
1.0.0.beta.1
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0.rc1
2.1.0.rc2
2.1.1
2.2.0
Fixed in
2.2.1
References
Updated Feb 22, 2024 · Source: OSV.dev |