What is CVE-2026-73492?
CVE-2026-73492 is a vulnerability in the Loofah library where Loofah::HTML5::Scrub.allowed_uri? fails to reject 'javascript:' or 'vbscript:' URIs encoded with semicolon-less numeric character references. This affects versions 2.25.0 to 2.25.2, and upgrading to 2.25.3 or later is recommended to mitigate potential XSS risks.
Azərbaycanca: CVE-2026-73492, Loofah kitabxanasında aşkarlanmış boşluqdur. 2.25.0-dan 2.25.2-yə qədər versiyalarda Loofah::HTML5::Scrub.allowed_uri? funksiyası nömrə istinadları ilə saxlanılmış (semicolon olmadan) 'javascript:' və ya 'vbscript:' sxemlərini bloklamır. Təsirlənən versiyaları dərhal 2.25.3+ yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which library is affected by CVE-2026-73492 and which function is vulnerable?
This vulnerability affects the Loofah library. The flaw is in the Loofah::HTML5::Scrub.allowed_uri? function.
To which version should users upgrade to mitigate CVE-2026-73492?
Upgrading to version 2.25.3 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.