VDB

GCVE-VVD-MAGEIA-2020-176

GCVE-VVD-MAGEIA-2020-176
Advisory Published
Vulnetix · Advisory published August 18, 2020
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False. (CVE-2020-6816) Regular expression denial of service. (CVE-2020-6817)

Affected Products

VendorProductVersionsPlatforms
Mageianvidia3900 (affected), 390.138-1.mga7.nonfree (unaffected)
Mageiapython-bleach0 (affected), 3.1.4-1.mga7 (unaffected), 0 (affected), 3.1.4-1.mga7 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›