CVE-2021-23980

Severity
6.1MEDIUM
EPSS
0.5%
top 36.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Latest updateMar 5

Description

A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

PyPIbleach< 3.3.0+1
NVDmozilla/bleach< 3.3.0
CVEListV5mozilla/mozilla_bleachunspecified3.3.0
Debianpython-bleach< 3.2.1-2.1+3

🔴Vulnerability Details

5
CVEList
CVE-2021-23980: A mutation XSS affects users calling bleach2023-02-16
OSV
CVE-2021-23980: A mutation XSS affects users calling bleach2023-02-16
OSV
Cross-site scripting in Bleach2021-02-02
OSV
CVE-2021-23980: In Mozilla Bleach before 32021-02-02
GHSA
Cross-site scripting in Bleach2021-02-02

📋Vendor Advisories

4
Ubuntu
Bleach vulnerabilities2026-03-05
Microsoft
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tag2023-02-14
Red Hat
python-bleach: Mutation cross-site scripting in bleach.clean2021-02-02
Debian
CVE-2021-23980: python-bleach - A mutation XSS affects users calling bleach.clean with all of: svg or math in th...2021
CVE-2021-23980 (MEDIUM CVSS 6.1) | A mutation XSS affects users callin | cvebase.io