Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-gj48-438w-jh9v
  • PyPI/bleach
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes 16 Jun
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-g75f-g53v-794x
  • PyPI/bleach
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning 16 Jun
  • No fix available
  • Severity - 4.3 (Medium)
GHSA-8rfp-98v4-mmr6
  • PyPI/bleach
Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output 16 Jun
  • Fix available
  • Severity - 0.0 (None)
GHSA-vv2x-vrpj-qqpq
  • PyPI/bleach
Cross-site scripting in Bleach 02 Feb 2021
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2021-865
  • PyPI/bleach
  • github.com/mozilla/bleach
See record for full details 02 Feb 2021
  • Fix available
GHSA-vqhp-cxgc-6wmm
  • PyPI/bleach
regular expression denial-of-service (ReDoS) in Bleach 30 Mar 2020
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2020-340
  • PyPI/bleach
See record for full details 30 Mar 2020
  • Fix available
PYSEC-2020-27
  • PyPI/bleach
See record for full details 24 Mar 2020
  • Fix available
PYSEC-2020-28
  • PyPI/bleach
See record for full details 24 Mar 2020
  • Fix available
GHSA-m6xf-fq7q-8743
  • PyPI/bleach
Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tag 24 Mar 2020
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-q65m-pv3f-wr5r
  • PyPI/bleach
XSS in Bleach when noscript and raw tag whitelisted 24 Feb 2020
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-m9mq-p2f9-cfqv
  • PyPI/bleach
Bleach URI Scheme Restriction Bypass 04 Jan 2019
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2018-51
  • PyPI/bleach
  • github.com/mozilla/bleach
See record for full details 07 Mar 2018
  • Fix available