Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-23980

21
FAUCET Score

CVE-2021-23980 is a medium-severity mutation Cross-Site Scripting (XSS) vulnerability affecting the mozilla bleach library. It occurs when bleach.clean is used with specific, non-default configurations involving SVG/Math tags, P/BR tags, and certain other tags, alongside strip_comments=False. The vulnerability has a CVSS score of 6.1, indicating a network-based attack requiring user interaction, with potential for low impact on confidentiality and integrity. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been observed.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.3.0CPE matchmatch criteria
cpe:2.3:a:mozilla:bleach:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.48%
Probability of exploitation in next 30 days
EPSS Percentile
38.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0048 is in the 41st percentile among its peer group of 26,220 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

pippatch availablevia ghsa
Product: bleachFixed in: 3.3.0
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: automation-hub-0:4.2.2-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: python3-django-0:2.2.18-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: python-bleach-0:3.3.0-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: automation-hub-0:4.2.2-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: python3-django-0:2.2.18-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: python-bleach-0:3.3.0-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: python-bleach-allowlist-0:1.0.3-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: python-galaxy-importer-0:0.2.15-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: python-galaxy-ng-0:4.2.2-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 7Fixed in: python-pulp-ansible-1:0.5.6-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: python-bleach-allowlist-0:1.0.3-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: python-galaxy-importer-0:0.2.15-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: python-pulp-ansible-1:0.5.6-1.el8pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Automation Hub 4.2 for RHEL 8Fixed in: python-galaxy-ng-0:4.2.2-1.el8pc
View patch
ubuntupatch availablevia ubuntu_usn
Product: python-bleach (bionic)Fixed in: 2.1.2-1ubuntu0.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: python-bleach (focal)Fixed in: 3.1.1-1ubuntu0.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: python-bleach (xenial)Fixed in: 1.4.2-1ubuntu0.1~esm1
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (4)

ubuntuUSN-8077-1

Bleach vulnerabilities

Mar 5, 2026
microsoft2023-Feb/CVE-2021-23980Moderate

A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.

Feb 14, 2023
pipGHSA-vv2x-vrpj-qqpqmedium

Cross-site scripting in Bleach

Feb 2, 2021
redhatCVE-2021-23980Moderate

python-bleach: Mutation cross-site scripting in bleach.clean

Feb 2, 2021

References

bugzilla.mozilla.org / show_bug.cgi
ExploitIssue Tracking
github.com / mozilla/bleach/security/advisories/GHSA-vv2x-vrpj-qqpq
Vendor Advisory