VDB
GCVE-VVD-MAGEIA-2021-260
GCVE-VVD-MAGEIA-2021-260
Advisory Published
It was reported that python-bleach, a whitelist-based HTML-sanitizing
library, is prone to a mutation XSS vulnerability in bleach.clean when "svg"
or "math" are in the allowed tags, 'p' or "br" are in allowed tags, "style",
"title", "noscript", "script", "textarea", "noframes", "iframe", or "xmp" are
in allowed tags and 'strip_comments=False' is set (CVE-2021-23980).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | python-bleach | 0 (affected), 3.1.4-1.1.mga7 (unaffected) | — |
| Mageia | python-bleach | 0 (affected), 3.3.0-1.mga8 (unaffected) | — |
Aliases
Transitive aliases
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.