Executive brief
Bleach is a Python library used to clean and sanitize HTML to prevent malicious code from running in web browsers. A flaw in its URI sanitization allows certain disallowed links (like those starting with 'javascript:') to pass through if they contain specific invisible Unicode characters. While most modern browsers will not execute these malformed links, they could become dangerous if another system processes the text further or if the browser's behavior changes, potentially leading to unauthorized script execution.
Technical details
A vulnerability in bleach.clean allows disallowed URI schemes (e.g., 'javascript:') to bypass the protocol allowlist if they contain Unicode characters above U+00A0, such as a Zero Width Space (U+200B). The root cause is an incomplete list of disallowed inputs (CWE-184) in the URI scheme validation logic, which fails to account for non-ASCII characters that break RFC 3986 compliance but may be normalized later. While modern browsers typically treat these as invalid URIs and do not execute them, a security risk exists if downstream systems perform Unicode normalization (stripping the invisible characters) before rendering the HTML. This could re-enable the 'javascript:' scheme and lead to Cross-Site Scripting (XSS). The issue is fixed in version 6.4.0.
Affected products
- Mozilla bleach <= 6.3.0
Timeline
- 2026-06-05: advisory: Initial advisory published by maintainer
- 2026-06-16: disclosed: GitHub Advisory Database entry updated
- 2026-06-05: patched: Version 6.4.0 released