CVE-2021-42576: Microco Bluemonday
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Affected products
- Microco Bluemonday: before 1.0.16 (fixed in 1.0.16)
- Python Pybluemonday: before 0.0.8 (fixed in 0.0.8)
Published 2021-10-18. Last modified 2026-06-17.