In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
https://www.debian.org/security/2019/dsa-4554
https://usn.ubuntu.com/4498-1/
https://security.netapp.com/advisory/ntap-20191122-0003/