| Release | Version |
|---|---|
| bullseye | 2.7.0+dfsg-1 |
| bullseye (security) | 2.7.0+dfsg-1+deb11u1 |
| bookworm | 2.19.1-1 |
| trixie | 2.24.0-1 |
| forky | 2.25.2-1 |
| sid | 2.25.2-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-73492 | vulnerable | vulnerable | vulnerable (no DSA) | fixed | fixed | Loofah is a general library for manipulating and transforming HTML/XML ... |
| CVE-2026-73491 | vulnerable | vulnerable | vulnerable (no DSA) | fixed | fixed | Loofah is a general library for manipulating and transforming HTML/XML ... |
| CVE-2026-73490 | vulnerable | vulnerable | vulnerable (no DSA) | fixed | fixed | Loofah is a general library for manipulating and transforming HTML/XML ... |
| Bug | Description |
|---|---|
| CVE-2022-23516 | Loofah is a general library for manipulating and transforming HTML/XML ... |
| CVE-2022-23515 | Loofah is a general library for manipulating and transforming HTML/XML ... |
| CVE-2022-23514 | Loofah is a general library for manipulating and transforming HTML/XML ... |
| CVE-2019-15587 | In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may o ... |
| CVE-2018-16468 | In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may ... |
| CVE-2018-8048 | In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attribu ... |
| DSA / DLA | Description |
|---|---|
| DLA-3901-1 | ruby-loofah - security update |
| DLA-3565-1 | ruby-loofah - security update |
| DSA-4554-1 | ruby-loofah - security update |
| DSA-4364-1 | ruby-loofah - security update |
| DSA-4171-1 | ruby-loofah - security update |