{"id":"CVE-2018-7753","details":"An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.","aliases":["GHSA-m9mq-p2f9-cfqv","PYSEC-2018-51"],"modified":"2026-07-22T19:07:39.938196331Z","published":"2018-03-07T23:29:00.273Z","related":["openSUSE-SU-2024:11219-1","openSUSE-SU-2024:14134-1","openSUSE-SU-2026:11323-1"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://bugs.debian.org/892252"},{"type":"ADVISORY","url":"https://github.com/mozilla/bleach/releases/tag/v2.1.3"},{"type":"FIX","url":"https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ef"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}