{"id":"CVE-2016-9909","details":"The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the \u003c (less than) character in attribute values.","aliases":["GHSA-v9v9-xffq-rwr4","PYSEC-2017-14"],"modified":"2026-05-17T11:54:47.425576458Z","published":"2017-02-22T16:59:00.380Z","database_specific":{},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95132"},{"type":"ADVISORY","url":"https://github.com/html5lib/html5lib-python/issues/11"},{"type":"ADVISORY","url":"https://github.com/html5lib/html5lib-python/issues/12"},{"type":"ADVISORY","url":"https://html5lib.readthedocs.io/en/latest/changes.html#b9"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/12/06/5"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/12/08/8"},{"type":"FIX","url":"https://github.com/html5lib/html5lib-python/commit/9b8d8eb5afbc066b7fac9390f5ec75e5e8a7cab7"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}