Executive brief
In Mozilla Bleach before 3.1.4, `bleach.clean` behavior parsing style attributes could result in a regular expression denial of service (ReDoS).
Affected products
- PyPI bleach
Junglewise Threat Intelligence
CVE-2020-6817 · Severity: low · CVSS 3.1 · Published 2020-03-30
Technologies: bleach (PyPI). Vendors: PyPI.
In Mozilla Bleach before 3.1.4, `bleach.clean` behavior parsing style attributes could result in a regular expression denial of service (ReDoS).