{"id":"CVE-2021-23980","aliases":["GHSA-vv2x-vrpj-qqpq","PYSEC-2021-865"],"url":"https://o3.security/vulnerability/CVE-2021-23980","summary":"Cross-site scripting in Bleach","details":"A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.","published":"2023-02-16T22:15:10.713Z","modified":"2026-07-22T09:44:37.587647931Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00479,"percentile":0.39481,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"bleach","fixedVersion":"3.3.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/mozilla/bleach/security/advisories/GHSA-vv2x-vrpj-qqpq"},{"type":"REPORT","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2021-23980"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-22T09:44:37.587647931Z"}}