CVE-2018-7753
published 2018-03-07CVE-2018-7753: An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities…
PriorityP340critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.20%
80.4th percentile
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-bleach | < python-bleach 2.1.3-1 (bookworm) | python-bleach 2.1.3-1 (bookworm) |
| mozilla | bleach | — | — |
| mozilla | bleach | — | — |
| mozilla | bleach | — | — |
| mozilla | bleach | >= 2.1.0 < 2.1.3 | 2.1.3 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python-bleach vulnerabilities
osv·2026-03-05·CVSS 9.8
CVE-2018-7753 [CRITICAL] python-bleach vulnerabilities
python-bleach vulnerabilities
It was discovered that Bleach did not properly sanitize URI attributes
containing character entities. An attacker could possibly use this issue
to construct a URI with a disallowed scheme that would bypass
sanitization, leading to cross-site scripting. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-7753)
Yaniv Nizry discovered that Bleach was vulnerable to a mutation
cross-site scripting issue when sanitizing HTML with the noscript tag
and a raw tag in the allowed tags list. An attacker could possibly
use this issue to inject malicious content, leading to cross-site
scripting. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-6802)
Yaniv Nizry discovered that Bleach was vulnerable to a mutation
cross-site scripting issue when sanitizing HTML with R
GHSA
Bleach URI Scheme Restriction Bypass
ghsa·2019-01-04
CVE-2018-7753 [CRITICAL] CWE-20 Bleach URI Scheme Restriction Bypass
Bleach URI Scheme Restriction Bypass
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
OSV
Bleach URI Scheme Restriction Bypass
osv·2019-01-04
CVE-2018-7753 [CRITICAL] Bleach URI Scheme Restriction Bypass
Bleach URI Scheme Restriction Bypass
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
OSV
CVE-2018-7753: An issue was discovered in Bleach 2
osv·2018-03-07·CVSS 9.8
CVE-2018-7753 [CRITICAL] CVE-2018-7753: An issue was discovered in Bleach 2
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
Ubuntu
Bleach vulnerabilities
vendor_ubuntu·2026-03-05·CVSS 9.8
CVE-2018-7753 [CRITICAL] Bleach vulnerabilities
Title: Bleach vulnerabilities
Summary: Several security issues were fixed in Bleach.
It was discovered that Bleach did not properly sanitize URI attributes
containing character entities. An attacker could possibly use this issue
to construct a URI with a disallowed scheme that would bypass
sanitization, leading to cross-site scripting. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-7753)
Yaniv Nizry discovered that Bleach was vulnerable to a mutation
cross-site scripting issue when sanitizing HTML with the noscript tag
and a raw tag in the allowed tags list. An attacker could possibly
use this issue to inject malicious content, leading to cross-site
scripting. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-6802)
Yaniv Nizry discovered that Bleach was vulnerable to a mutatio
Debian
CVE-2018-7753: python-bleach - An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI v...
vendor_debian·2018·CVSS 9.8
CVE-2018-7753 [CRITICAL] CVE-2018-7753: python-bleach - An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI v...
An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
Scope: local
bookworm: resolved (fixed in 2.1.3-1)
bullseye: resolved (fixed in 2.1.3-1)
forky: resolved (fixed in 2.1.3-1)
sid: resolved (fixed in 2.1.3-1)
trixie: resolved (fixed in 2.1.3-1)
No detection rules found.
Bugzilla
CVE-2018-7753 python-bleach: URI Scheme Restriction Bypass with character entities [fedora-26]
bugzilla·2018-03-19·CVSS 9.8
CVE-2018-7753 [CRITICAL] CVE-2018-7753 python-bleach: URI Scheme Restriction Bypass with character entities [fedora-26]
CVE-2018-7753 python-bleach: URI Scheme Restriction Bypass with character entities [fedora-26]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-26.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templ
Bugzilla
CVE-2018-7753 python-bleach: URI Scheme Restriction Bypass with character entities
bugzilla·2018-03-19·CVSS 9.8
CVE-2018-7753 [CRITICAL] CVE-2018-7753 python-bleach: URI Scheme Restriction Bypass with character entities
CVE-2018-7753 python-bleach: URI Scheme Restriction Bypass with character entities
A flaw was found in python-bleach version 2.1. Affected versions of this package are vulnerable to URI Scheme Restriction Bypass. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=892252
Patch:
https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ef
Discussion:
Created python-bleach tracking bugs for this issue:
Affects: fedora-26 [bug 1558268]
https://bugs.debian.org/892252https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35efhttps://github.com/mozilla/bleach/releases/tag/v2.1.3https://bugs.debian.org/892252https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35efhttps://github.com/mozilla/bleach/releases/tag/v2.1.3
2018-03-07
Published