VDB

GCVE-VVD-MAGEIA-2021-260

GCVE-VVD-MAGEIA-2021-260
Advisory Published
Vulnetix · Advisory published June 16, 2021
It was reported that python-bleach, a whitelist-based HTML-sanitizing library, is prone to a mutation XSS vulnerability in bleach.clean when "svg" or "math" are in the allowed tags, 'p' or "br" are in allowed tags, "style", "title", "noscript", "script", "textarea", "noframes", "iframe", or "xmp" are in allowed tags and 'strip_comments=False' is set (CVE-2021-23980).

Affected Products

VendorProductVersionsPlatforms
Mageiapython-bleach0 (affected), 3.1.4-1.1.mga7 (unaffected)
Mageiapython-bleach0 (affected), 3.3.0-1.mga8 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›