© 2025-2026 PySpect
First version without a known vulnerability: 6.4.0
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
Fixed in: 6.4.0
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
Fixed in: 6.4.0
Cross-site scripting in Bleach
Fixed in: 3.3.0, 79b7a3c5e56a09d1d323a5006afa59b56162eb13
regular expression denial-of-service (ReDoS) in Bleach
Fixed in: 3.1.4
Bleach vulnerable to mutation XSS via whitelisted math or svg and raw tag
Fixed in: 3.1.2
XSS in Bleach when noscript and raw tag whitelisted
Fixed in: 3.1.1
Bleach URI Scheme Restriction Bypass
Fixed in: 2.1.3, c5df5789ec3471a31311f42c2d19fc2cf21b35ef