bleach.clean
behavior parsing style attributes could result in a regular expression denial of service (ReDoS).
Calls to bleach.clean
with an allowed tag with an allowed style
attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']})
.
3.1.4
do not whitelist the style attribute in bleach.clean
calls
limit input string length
If you have any questions or comments about this advisory: