bleach vulnerabilities
CVEs whose affected-version data names the bleach package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
GHSA-8rfp-98v4-mmr6Low· 0.0Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
▾ Sunlitbleach · bleachvia OSV
GHSA-g75f-g53v-794xMedium· 4.3Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
▾ Sunlitbleach · bleachvia GHSA
GHSA-gj48-438w-jh9vMedium· 6.1Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
▾ Sunlitbleach · bleachvia OSV
CVE-2021-23980Medium· 6.1Cross-site scripting in Bleach
Cross-site scripting in Bleach
▾ Sunlitbleach · bleachEPSS 0.48%via OSV
CVE-2020-6817High· 7.5regular expression denial-of-service (ReDoS) in Bleach
regular expression denial-of-service (ReDoS) in Bleach
▾ Twilightbleach · bleachEPSS 0.72%via OSV
CVE-2020-6816Medium· 6.1Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tag
Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tag
▾ Sunlitbleach · bleachEPSS 1.3%via OSV
CVE-2020-6802Medium· 6.1XSS in Bleach when noscript and raw tag whitelisted
XSS in Bleach when noscript and raw tag whitelisted
▾ Sunlitbleach · bleachEPSS 1.7%via OSV