{"id":"CVE-2018-7753","details":"An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.","aliases":["GHSA-m9mq-p2f9-cfqv","PYSEC-2018-51"],"modified":"2026-07-22T09:44:31.451574553Z","published":"2018-03-07T23:29:00.273Z","related":["openSUSE-SU-2024:11219-1","openSUSE-SU-2024:14134-1","openSUSE-SU-2026:11323-1"],"references":[{"type":"ADVISORY","url":"https://bugs.debian.org/892252"},{"type":"ADVISORY","url":"https://github.com/mozilla/bleach/releases/tag/v2.1.3"},{"type":"FIX","url":"https://github.com/mozilla/bleach/commit/c5df5789ec3471a31311f42c2d19fc2cf21b35ef"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mozilla/bleach","events":[{"introduced":"cb5f2b865649cebc7bca5c9fba2dfe94aa982b6c"},{"last_affected":"35d051ca4b54a3a3b16c243cac3f3bb6678e69bb"},{"fixed":"c5df5789ec3471a31311f42c2d19fc2cf21b35ef"},{"fixed":"9584f42051c0039cb0f27a617e8ab3e945018cc6"}],"database_specific":{"source":["CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:mozilla:bleach:2.1:*:*:*:*:*:*:*","cpe:2.3:a:mozilla:bleach:2.1.1:*:*:*:*:*:*:*","cpe:2.3:a:mozilla:bleach:2.1.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.1"},{"last_affected":"2.1"},{"introduced":"2.1.1"},{"last_affected":"2.1.1"},{"introduced":"2.1.2"},{"last_affected":"2.1.2"}]}}],"versions":["2.1","2.1.1","2.1.2","v2.1.2","v2.1.1","v2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7753.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}