GHSA-8whx-365g-h9vv (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
21-Jul-2026 1
Originally appeared on RubySec.## Summary Loofah::HTML5::Scrub.allowed_uri? does not correctly reject javascript: URIs when the scheme is split or prefixed by the HTML5 named character references (tab) or
(line feed). This is a bypass of the fix for GHSA-46fp-8...
GHSA-8whx-365g-h9vv (loofah): Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references #ruby #rubydeveloper #rubyonrails #ruby #rubyonrails #programming #webdev #ghsa-8whx-365g-h9vv #(loofah): https://www.rubyonrails.ba/link/ghsa-8whx-365g-h9vv-loofah-loofah-allowed_uri-does-not-detect-javascript-uris-split-by-named-whitespace-character-references