CVE-2020-6817: High severity mozilla bleach vulnerability

Published Mar 30, 2020
·
Updated

Impact

bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS).

Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}).

Patches

3.1.4

Workarounds

do not whitelist the style attribute in bleach.clean calls

limit input string length

References

https://bugzilla.mozilla.org/showbug.cgi?id=1623633 https://www.regular-expressions.info/redos.html https://blog.r2c.dev/posts/finding-python-redos-bugs-at-scale-using-dlint-and-r2c/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6817

Credits

Reported by schwag09 of r2c

For more information If you have any questions or comments about this advisory:

Open an issue at https://github.com/mozilla/bleach/issues Email us at security@mozilla.org

Other sources

bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}).

Affected Software

2 affected componentsFixes available
Mozilla Bleach<3.1.4
pip/bleach<3.1.4
3.1.4

Event History

Mar 30, 2020
Advisory Published
via GitHub·07:45 PM
Feb 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-6817?

CVE-2020-6817 has been classified as a moderate severity vulnerability due to its potential for regular expression denial of service (ReDoS).

2

How do I fix CVE-2020-6817?

To fix CVE-2020-6817, upgrade your Bleach package to version 3.1.4 or later.

3

Which versions of Bleach are affected by CVE-2020-6817?

Bleach versions prior to 3.1.4 are affected by CVE-2020-6817.

4

What type of vulnerability is CVE-2020-6817?

CVE-2020-6817 is a regular expression denial of service (ReDoS) vulnerability.

5

In which scenarios does CVE-2020-6817 occur?

CVE-2020-6817 occurs when using bleach.clean with allowed tags that include an allowed style attribute.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203