chore(deps): update dependency bleach to v6 [security] - #1490
chore(deps): update dependency bleach to v6 [security]#1490renovate-bot wants to merge 1 commit into
Conversation
|
/gcbrun |
There was a problem hiding this comment.
Code Review
This pull request updates the bleach dependency to version 6.4.0 in requirements.txt. The reviewer correctly points out that bleach is deprecated and unmaintained as of this version, and recommends migrating to an actively maintained alternative like nh3 to mitigate long-term security risks.
| Flask==2.3.3 | ||
| Flask-PyMongo==2.3.0 | ||
| bleach==5.0.1 | ||
| bleach==6.4.0 |
There was a problem hiding this comment.
Bleach is officially deprecated and no longer maintained as of its v6.4.0 release (see Mozilla's announcement). Since Bleach is an HTML sanitization library, using an unmaintained package poses a long-term security risk as new vulnerabilities will not be patched.
It is highly recommended to plan a migration to an actively maintained alternative, such as nh3 (Python bindings for the Rust-based ammonia HTML sanitizer).
This PR contains the following updates:
==5.0.1→==6.4.0Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
GHSA-8rfp-98v4-mmr6
More information
Details
Impact
A possible XSS bypass affects users calling
bleach.cleanwith all of:ain the allowed tagshrefin allowed attributesThe
bleach.cleansanitizer outputs URIs containing disallowed scheme patterns that it should be stripping. However, because the inserted Unicode characters make the scheme invalid per RFC 3986, modern browsers do not execute these as javascript: URIs. The practical security impact is limited to:This is not a direct XSS vulnerability.
Python code example from reporter with Bleach v6.3.0 and Python 3.13:
Output:
Patches
Users should upgrade to Bleach 6.4.0.
Workarounds
Pre-process content removing non-ASCII characters from URI schemes before sanitizing with
bleach.clean.A strong Content-Security-Policy without unsafe-inline and unsafe-eval script-srcs will also help mitigate the risk.
References
Reported by
Reported by codeant from CodeAnt AI.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
GHSA-gj48-438w-jh9v
More information
Details
Summary
Bleach
clean()/Cleaner()fails to sanitize dangerous URI schemes in allowedformactionattributes.Bleach applies URI protocol sanitization only to attributes listed in
attr_val_is_uri. While URI-bearing attributes such asaction,href,src, andposterare included in that set,formactionis not. As a result, if a downstream application explicitly allowsformactionon submit-capable controls in untrusted HTML, Bleach preserves dangerous values such asjavascript:alert(1)instead of stripping them.This can lead to submit-triggered JavaScript execution in applications that rely on Bleach to sanitize untrusted HTML and allow the relevant tag/attribute combination.
Details
The issue appears to be a URI-sanitization coverage gap in Bleach’s sanitizer logic.
Relevant code paths:
bleach/sanitizer.py—BleachSanitizerFilter.allow_token(around line 553)bleach/_vendor/html5lib/filters/sanitizer.py—attr_val_is_uri(around line 525)In
BleachSanitizerFilter.allow_token, URI protocol sanitization is only applied when:However,
(None, 'formaction')is currently missing fromattr_val_is_uri.This creates an inconsistency where
actionis protocol-sanitized, butformactionis not.As a result, if a downstream application allows:
<button>or<input>formactionattributethen Bleach preserves dangerous URI schemes such as
javascript:informaction.Examples of affected submit-capable controls include:
<button>(default submit behavior unlesstype="button"is set)<input type="submit"><input type="image">This appears to be a real library-side sanitizer gap rather than only an application misuse issue, because Bleach already treats similar URI-bearing attributes (such as
action) as protocol-sensitive and sanitizes them.Suggested minimal fix:
Add:
to
attr_val_is_uriin:bleach/_vendor/html5lib/filters/sanitizer.pyI also prepared a minimal patch and focused regression tests if helpful.
PoC
Below are minimal reproductions using
bleach.clean().1)
<button>Actual output:
Expected output:
2)
<input type="submit">Actual output:
Expected output:
3)
<input type="image">Actual output:
Expected output:
Impact
This is a client-side HTML sanitization bypass / dangerous URI preservation issue.
If an application relies on Bleach to sanitize untrusted HTML and explicitly allows:
formaction<button>or<input>then Bleach can emit sanitized output that still contains a dangerous
javascript:URI informaction.That can lead to submit-triggered JavaScript execution when the user activates the control.
Impact is limited to configurations that explicitly allow the relevant tag/attribute combination, but the issue is still security-relevant because:
formactionis a real browser sinkactionI would currently assess this as Medium severity.
If useful, I also have:
a minimal patch
focused regression tests for:
<button formaction="javascript:..."><input type="submit" formaction="javascript:..."><input type="image" formaction="javascript:...">formaction="/submit"is preservedSeverity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
mozilla/bleach (bleach)
v6.4.0Compare Source
NOTE: 2026-06-05: Bleach is no longer maintained. There will be no future
releases including for security issues.
See issue:
<https://github.com/mozilla/bleach/issues/698>__Backwards incompatible changes
Security fixes
Fix bug
2023812/ GHSA-8rfp-98v4-mmr6.Fix XSS issue with sanitize_uri_value where disallowed schemes with
Unicode invisible characters wouldn't be rejected.
For example::
import bleach
payload1 = 'Click'
result1 = bleach.clean(payload1)
print(repr(result1))
outputs::
'Click'
See the advisory for details.
Fix GHSA-gj48-438w-jh9v.
Fix issue where URI sanitization wasn't happening in formaction attributes.
See the advisory for details.
Bug fixes
Add support for pypy 3.11. (#764)
Drop version max in tinycss2 pin. (#772)
This removes one of the things we had to keep checking and updating. Users
now own the responsibility for correctness with the version of tinycss2
they're using.
v6.3.0Compare Source
Backwards incompatible changes
Security fixes
None
Bug fixes
v6.2.0Compare Source
Backwards incompatible changes
Security fixes
None
Bug fixes
v6.1.0Compare Source
Backwards incompatible changes
Security fixes
None
Bug fixes
v6.0.0Compare Source
Backwards incompatible changes
bleach.clean,bleach.sanitizer.Cleaner,bleach.html5lib_shim.BleachHTMLParser: thetagsandprotocolsarguments were changed from lists to sets.
Old pre-6.0.0:
.. code-block:: python
bleach.clean(
"some text",
tags=["a", "p", "img"],
^ ^ list
^ ^ list
New 6.0.0 and later:
.. code-block:: python
^ ^ set
^ ^ set
bleach.linkify,bleach.linkifier.Linker: theskip_tagsandrecognized_tagsarguments were changed from lists to sets.Old pre-6.0.0:
.. code-block:: python
bleach.linkify(
"some text",
skip_tags=["pre"],
^ ^ list
^ ^ list
^ ^ ^ list
|
| list concatenation
New 6.0.0 and later:
.. code-block:: python
^ ^ set
^ ^ set
^ ^ ^ set
|
| union operator
bleach.sanitizer.BleachSanitizerFilter:strip_allowed_elementsis nowstrip_allowed_tags. We now use "tags" everywhere rather than a mishmashof "tags" in some places and "elements" in others.
Security fixes
None
Bug fixes
Add support for Python 3.11. (#675)
Fix API weirness in
BleachSanitizerFilter. (#649)We're using "tags" instead of "elements" everywhere--no more weird
overloading of "elements" anymore.
Also, it no longer calls the superclass constructor.
Add warning when
css_sanitizerisn't set, but thestyleattribute is allowed. (#676)
Fix linkify handling of character entities. (#501)
Rework dev dependencies to use
requirements-dev.txtandrequirements-flake8.txtinstead of extras.Fix project infrastructure to be tox-based so it's easier to have CI
run the same things we're running in development and with flake8
in an isolated environment.
Update action versions in CI.
Switch to f-strings where possible. Make tests parametrized to be
easier to read/maintain.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.