{"id":"CVE-2018-7753","aliases":["GHSA-m9mq-p2f9-cfqv","PYSEC-2018-51"],"url":"https://o3.security/vulnerability/CVE-2018-7753","summary":"Bleach URI Scheme Restriction Bypass","details":"An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.","published":"2018-03-07T23:29:00.273Z","modified":"2026-07-22T09:44:31.451574553Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"bleach","fixedVersion":"2.1.3"}],"fix":{"url":"https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ef","label":"mozilla/bleach@c5df578"},"references":[{"type":"ADVISORY","url":"https://bugs.debian.org/892252"},{"type":"ADVISORY","url":"https://github.com/mozilla/bleach/releases/tag/v2.1.3"},{"type":"FIX","url":"https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ef"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-22T09:44:31.451574553Z"}}