NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #373 most downloaded on PyPI
An easy safelist-based HTML-sanitizing tool.
Last release 4 months ago
05 Jun 2026
Release timing varies
gaps range from 2 weeks to 13 months
Most releases are documented
notes for 44 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
17 years old
61 releases · first in 2010
NOTE: 2026-06-05: Bleach is no longer maintained. There will be no future releases including for security issues. See issue: <https://github.com/mozil
NOTE: 2026-06-05: Bleach is no longer maintained. There will be no future
releases including for security issues.
See issue: <https://github.com/mozilla/bleach/issues/698>__
Backwards incompatible changes
Security fixes
Fix bug 2023812 / GHSA-8rfp-98v4-mmr6.
Fix XSS issue with sanitize_uri_value where disallowed schemes with
Unicode invisible characters wouldn't be rejected.
For example::
import bleach
payload1 = 'Click'
result1 = bleach.clean(payload1)
print(repr(result1))
outputs::
'Click'
See the advisory for details.
Fix GHSA-gj48-438w-jh9v.
Fix issue where URI sanitization wasn't happening in formaction attributes.
See the advisory for details.
Bug fixes
One column per quarter.
Dropped support for Python 3.9.
Dropped support for Python 3.8.
Dropped support for Python 3.7.
Backwards incompatible changes
Security fixes
None
Bug fixes
bleach.clean , bleach.sanitizer.Cleaner , bleach.html5lib_shim.BleachHTMLParser : the tags and protocols arguments were changed from lists to sets.
Backwards incompatible changes
bleach.clean, bleach.sanitizer.Cleaner,
bleach.html5lib_shim.BleachHTMLParser: the tags and protocols
arguments were changed from lists to sets.
Old pre-6.0.0:
.. code-block:: python
bleach.clean(
"some text",
tags=["a", "p", "img"],
# ^ ^ list
protocols=["http", "https"],
# ^ ^ list
)
New 6.0.0 and later:
.. code-block:: python
bleach.clean(
"some text",
tags={"a", "p", "img"},
# ^ ^ set
protocols={"http", "https"},
# ^ ^ set
)
bleach.linkify, bleach.linkifier.Linker: the skip_tags and
recognized_tags arguments were changed from lists to sets.
Old pre-6.0.0:
.. code-block:: python
bleach.linkify(
"some text",
skip_tags=["pre"],
# ^ ^ list
)
linker = Linker(
skip_tags=["pre"],
# ^ ^ list
recognized_tags=html5lib_shim.HTML_TAGS + ["custom-element"],
# ^ ^ ^ list
# |
# | list concatenation
)
New 6.0.0 and later:
.. code-block:: python
bleach.linkify(
"some text",
skip_tags={"pre"},
# ^ ^ set
)
linker = Linker(
skip_tags={"pre"},
# ^ ^ set
recognized_tags=html5lib_shim.HTML_TAGS | {"custom-element"},
# ^ ^ ^ set
# |
# | union operator
)
bleach.sanitizer.BleachSanitizerFilter: strip_allowed_elements is now
strip_allowed_tags. We now use "tags" everywhere rather than a mishmash
of "tags" in some places and "elements" in others.
Security fixes
None
Bug fixes
Add support for Python 3.11. (#675)
Fix API weirness in BleachSanitizerFilter. (#649)
We're using "tags" instead of "elements" everywhere--no more weird
overloading of "elements" anymore.
Also, it no longer calls the superclass constructor.
Add warning when css_sanitizer isn't set, but the style
attribute is allowed. (#676)
Fix linkify handling of character entities. (#501)
Rework dev dependencies to use requirements-dev.txt and
requirements-flake8.txt instead of extras.
Fix project infrastructure to be tox-based so it's easier to have CI
run the same things we're running in development and with flake8
in an isolated environment.
Update action versions in CI.
Switch to f-strings where possible. Make tests parametrized to be
easier to read/maintain.
Add missing comma to tinycss2 require. Thank you, @shadchin !
Bugs
Add missing comma to tinycss2 require. Thank you, @shadchin!
Add url parse tests based on wpt url tests. (#688)
Support scheme-less urls if "https" is in allow list. (#662)
Handle escaping < in edge cases where it doesn't start a tag. (#544)
Fix reference warnings in docs. (#660)
Correctly urlencode email address parts. Thank you, @larseggert! (#659)
Security fixes
None
Bug fixes
Add missing comma to tinycss2 require. Thank you, @shadchin!
Add url parse tests based on wpt url tests. (#688)
Support scheme-less urls if "https" is in allow list. (#662)
Handle escaping < in edge cases where it doesn't start a tag. (#544)
Fix reference warnings in docs. (#660)
Correctly urlencode email address parts. Thank you, @larseggert! (#659)
clean and linkify now preserve the order of HTML attributes. Thank you, @askoretskly!
Backwards incompatible changes
clean and linkify now preserve the order of HTML attributes. Thank
you, @askoretskly! (#566)
CSS sanitization in style tags is completely different now. If you're using
Bleach clean to sanitize css in style tags, you'll need to update your
code and you'll need to install the css extras::
pip install 'bleach[css]'
See the documentation on sanitizing CSS for how to do it <https://bleach.readthedocs.io/en/latest/clean.html#sanitizing-css>_. (#633)
Bug fixes
Update sanitizer clean to use vendored 3.6.14 stdlib urllib.parse to fix test failures on Python 3.9 #536
Bug fixes
Features
Security fixes
None
Bug fixes
Drop support for unsupported Python versions <3.6 #520
Security fixes
None
Features
Backwards incompatible changes
Security fixes
None
Features
add more tests for CVE-2021-23980 / GHSA-vv2x-vrpj-qqpq
None
Features
Bug fixes
clean escapes HTML comments even when strip_comments=False
Backwards incompatible changes
Security fixes
Features
None
Bug fixes
None
fix clean and linkify raising ValueErrors for certain inputs. Thank you @Google-Autofuzz.
Security fixes
None
Features
None
Bug fixes
Migrate CI to Github Actions. Thank you @hugovk.
Security fixes
None
Features
Bug fixes
suppress html5lib sanitizer DeprecationWarnings
Security fixes
None
Features
None
Bug fixes
html5lib dependency to version 1.1.0. Thank you Sam Sneddon.
Security fixes
None
Features
None
Bug fixes
html5lib dependency to version 1.1.0. Thank you Sam Sneddon.replace missing setuptools dependency with packaging. Thank you Benjamin Peterson.
Security fixes
None
Features
None
Bug fixes
setuptools dependency with packaging. Thank you Benjamin Peterson.Calls to bleach.clean with an allowed tag with an allowed style attribute were vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['…
Security fixes
bleach.clean behavior parsing style attributes could result in a
regular expression denial of service (ReDoS).
Calls to bleach.clean with an allowed tag with an allowed
style attribute were vulnerable to ReDoS. For example,
bleach.clean(..., attributes={'a': ['style']}).
This issue was confirmed in Bleach versions v3.1.3, v3.1.2, v3.1.1, v3.1.0, v3.0.0, v2.1.4, and v2.1.3. Earlier versions used a similar regular expression and should be considered vulnerable too.
Anyone using Bleach <=v3.1.3 is encouraged to upgrade.
https://bugzilla.mozilla.org/show_bug.cgi?id=1623633
Backwards incompatible changes
Features
None
Bug fixes
None
Drop deprecated setup.py test support. Thank you, @jdufresne!
Security fixes
None
Backwards incompatible changes
Drop support for Python 3.4. Thank you, @hugovk!
Drop deprecated setup.py test support. Thank you, @jdufresne! (#507)
Features
Add support for Python 3.8. Thank you, @jdufresne!
Add support for PyPy 7. Thank you, @hugovk!
Add pypy3 testing to tox and travis. Thank you, @jdufresne!
Bug fixes
Add relative link to code of conduct. (#442)
Fix typo: curren -> current in tests/test_clean.py Thank you, timgates42! (#504)
Fix handling of non-ascii style attributes. Thank you, @sekineh! (#426)
Simplify tox configuration. Thank you, @jdufresne!
Make documentation reproducible. Thank you, @lamby!
Fix typos in code comments. Thank you, @zborboa-g!
Fix exception value testing. Thank you, @mastizada!
Fix parser-tags NoneType exception. Thank you, @bope!
Improve TLD support in linkify. Thank you, @pc-coholic!
…or xmp in the allowed tags whitelist were vulnerable to a mutation XSS.
Security fixes
bleach.clean behavior parsing embedded MathML and SVG content
with RCDATA tags did not match browser behavior and could result in
a mutation XSS.
Calls to bleach.clean with strip=False and math or
svg tags and one or more of the RCDATA tags script,
noscript, style, noframes, iframe, noembed, or
xmp in the allowed tags whitelist were vulnerable to a mutation
XSS.
This security issue was confirmed in Bleach version v3.1.1. Earlier versions are likely affected too.
Anyone using Bleach <=v3.1.1 is encouraged to upgrade.
https://bugzilla.mozilla.org/show_bug.cgi?id=1621692
Backwards incompatible changes
None
Features
None
Bug fixes
None
…style, noembed, noframes, iframe, and xmp) were vulnerable to a mutation XSS.
Security fixes
bleach.clean behavior parsing noscript tags did not match
browser behavior.
Calls to bleach.clean allowing noscript and one or more of
the raw text tags (title, textarea, script, style,
noembed, noframes, iframe, and xmp) were vulnerable
to a mutation XSS.
This security issue was confirmed in Bleach versions v2.1.4, v3.0.2, and v3.1.0. Earlier versions are probably affected too.
Anyone using Bleach <=v3.1.0 is highly encouraged to upgrade.
https://bugzilla.mozilla.org/show_bug.cgi?id=1615315
Backwards incompatible changes
None
Features
None
Bug fixes
None
Add recognized_tags argument to the linkify Linker class. This fixes issues when linkifying on its own and having some tags get escaped. It defaults t
Security fixes
None
Backwards incompatible changes
None
Features
recognized_tags argument to the linkify Linker class. This
fixes issues when linkifying on its own and having some tags get escaped.
It defaults to a list of HTML5 tags. Thank you, Chad Birch! (#409)Bug fixes
Add six>=1.9 to requirements. Thank you, Dave Shawley (#416)
Fix cases where attribute names could have invalid characters in them. (#419)
Fix problems with LinkifyFilter not being able to match links
across &. (#422)
Fix InputStreamWithMemory when the BleachHTMLParser is
parsing meta tags. (#431)
Fix doctests. (#357)
Merge Characters tokens after sanitizing them. This fixes issues in the LinkifyFilter where it was only linkifying parts of urls.
Security fixes
None
Backwards incompatible changes
None
Features
None
Bug fixes
Characters tokens after sanitizing them. This fixes issues in the
LinkifyFilter where it was only linkifying parts of urls. (#374)Support Python 3.7. It supported Python 3.7 just fine, but we added 3.7 to the list of Python environments we test so this is now officially supported
Security fixes
None
Backwards incompatible changes
None
Features
Bug fixes
list object has no attribute lower in clean. (#398)abbr getting escaped in linkify. (#400)A bunch of functions were moved from one module to another.
Security fixes
None
Backwards incompatible changes
A bunch of functions were moved from one module to another.
These were moved from bleach.sanitizer to bleach.html5lib_shim:
convert_entityconvert_entitiesmatch_entitynext_possible_entityBleachHTMLSerializerBleachHTMLTokenizerBleachHTMLParserThese functions and classes weren't documented and aren't part of the public API, but people read code and might be using them so we're considering it an incompatible API change.
If you're using them, you'll need to update your code.
Features
Bleach no longer depends on html5lib. html5lib==1.0.1 is now vendored into Bleach. You can remove it from your requirements file if none of your other requirements require html5lib.
This means Bleach will now work fine with other libraries that depend on html5lib regardless of what version of html5lib they require. (#386)
Bug fixes
Fixed tags getting added when using clean or linkify. This was a long-standing regression from the Bleach 2.0 rewrite. (#280, #392)
Fixed <isindex> getting replaced with a string. Now it gets escaped or
stripped depending on whether it's in the allowed tags or not. (#279)
Dropped support for Python 3.3.
Security fixes
None
Backwards incompatible changes
Features
None
Bug fixes
Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to co
Security fixes
Attributes that have URI values weren't properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized.
This security issue was introduced in Bleach 2.1. Anyone using Bleach 2.1 is highly encouraged to upgrade.
https://bugzilla.mozilla.org/show_bug.cgi?id=1442745
Backwards incompatible changes
None
Features
None
Bug fixes
Add deprecation warning for supporting html5lib-python < 1.0.
Security fixes
None
Backwards incompatible changes
None
Features
None
Bug fixes
Support html5lib-python 1.0.1. (#337)
Add deprecation warning for supporting html5lib-python < 1.0.
Switch to semver.
Fix setup.py opening files when LANG=.
Security fixes
None
Backwards incompatible changes
None
Features
None
Bug fixes
setup.py opening files when LANG=. (#324)Convert control characters (backspace particularly) to "?" preventing malicious copy-and-paste situations.
Security fixes
Convert control characters (backspace particularly) to "?" preventing malicious copy-and-paste situations. (#298)
See <https://github.com/mozilla/bleach/issues/298>_ for more details.
This affects all previous versions of Bleach. Check the comments on that issue for ways to alleviate the issue if you can't upgrade to Bleach 2.1.
Backwards incompatible changes
Redid versioning. bleach.VERSION is no longer available. Use the string
version at bleach.__version__ and parse it with
pkg_resources.parse_version. (#307)
clean, linkify: linkify and clean should only accept text types; thank you, Janusz! (#292)
clean, linkify: accept only unicode or utf-8-encoded str (#176)
Features
Bug fixes
bleach.clean() no longer unescapes entities including ones that are missing
a ; at the end which can happen in urls and other places. (#143)
linkify: fix http links inside of mailto links; thank you, sedrubal! (#300)
clarify security policy in docs (#303)
fix dependency specification for html5lib 1.0b8, 1.0b9, and 1.0b10; thank you, Zoltán! (#268)
add Bleach vs. html5lib comparison to README; thank you, Stu Cox! (#278)
fix KeyError exceptions on tags without href attr; thank you, Alex Defsen! (#273)
add test website and scripts to test bleach.clean() output in browser;
thank you, Greg Guthe!
Nothing published for this version
Nothing published for this version
Limit to html5lib >=0.999,<0.99999999 because of impending change to sanitizer api. #195
Security fixes
Changes
>=0.999,<0.99999999 because of impending change to
sanitizer api. #195linkify: Fix hang in linkify with parse_email=True.
Changes
linkify: Fix hang in linkify with parse_email=True. (#124)
linkify: Fix crash in linkify when removing a link that is a first-child. (#136)
Updated TLDs.
linkify: Don't remove exterior brackets when linkifying. (#146)
Consistent order of attributes in output.
Changes
Consistent order of attributes in output.
Python 3.4 support.
linkify: Update linkify to use etree type Treewalker instead of simpletree.
Changes
linkify: Update linkify to use etree type Treewalker instead of simpletree.
Updated html5lib to version >=0.999.
Update all code to be compatible with Python 3 and 2 using six.
Switch to Apache License.
Pin html5lib to version 0.95 for now due to major API break.
clean() no longer considers feed: an acceptable protocol due to inconsistencies in browser behavior.
clean() no longer considers feed: an acceptable protocol due to
inconsistencies in browser behavior.linkify() has changed considerably. Many keyword arguments have been replaced with a single callbacks list. Please see the documentation for more info
linkify() has changed considerably. Many keyword arguments have been
replaced with a single callbacks list. Please see the documentation for more
information.
Bleach will no longer consider unacceptable protocols when linkifying.
linkify() now takes a tokenizer argument that allows it to skip
sanitization.
delinkify() is gone.
Removed exception handling from _render. clean() and linkify() may
now throw.
linkify() correctly ignores case for protocols and domain names.
linkify() correctly handles markup within an <a> tag.
Nothing published for this version
Nothing published for this version
Fix parsing bare URLs when parse_email=True.
Fix hang in style attribute sanitizer.
Fix hang in style attribute sanitizer. (#61)
Allow / in style attribute values.
Fix tokenizer for html5lib 0.9.5.
linkify() now understands port numbers.
linkify() now understands port numbers. (#38)
Documented character encoding behavior. (#41)
Add an optional target argument to linkify().
Add delinkify() method. (#45)
Support subdomain whitelist for delinkify(). (#47, #48)
Make linkify() smarter about trailing punctuation.
Switch to SemVer git tags.
Make linkify() smarter about trailing punctuation. (#30)
Pass exc_info to logger during rendering issues.
Add wildcard key for attributes. (#19)
Make linkify() use the HTMLSanitizer tokenizer. (#36)
Fix URLs wrapped in parentheses. (#23)
Make linkify() UTF-8 safe. (#33)
linkify() works with 3rd level domains.
linkify() works with 3rd level domains. (#24)
clean() supports vendor prefixes in style values. (#31, #32)
Fix linkify() email escaping.
linkify() supports email addresses.
linkify() supports email addresses.
clean() supports callables in attributes filter.
linkify() doesn't drop trailing slashes.
linkify() doesn't drop trailing slashes. (#21)linkify() won't linkify 'libgl.so.1'. (#22)linkify() doesn’t drop trailing slashes. (#21)
linkify() won’t linkify ‘libgl.so.1’. (#22)
Sanitizing text fragments
Linkifying text fragments
Goals of Bleach
Bleach development
Bleach changes
Version 6.4.0 (June 5th, 2026)
Version 6.3.0 (October 27th, 2025)
Version 6.2.0 (October 29th, 2024)
Version 6.1.0 (October 6th, 2023)
Version 6.0.0 (January 23rd, 2023)
Version 5.0.1 (June 27th, 2022)
Version 5.0.0 (April 7th, 2022)
Version 4.1.0 (August 25th, 2021)
Version 4.0.0 (August 3rd, 2021)
Version 3.3.1 (July 14th, 2021)
Version 3.3.0 (February 1st, 2021)
Version 3.2.3 (January 26th, 2021)
Version 3.2.2 (January 20th, 2021)
Version 3.2.1 (September 18th, 2020)
Version 3.2.0 (September 16th, 2020)
Version 3.1.5 (April 29th, 2020)
Version 3.1.4 (March 24th, 2020)
Version 3.1.3 (March 17th, 2020)
Version 3.1.2 (March 11th, 2020)
Version 3.1.1 (February 13th, 2020)
Version 3.1.0 (January 9th, 2019)
Version 3.0.2 (October 11th, 2018)
Version 3.0.1 (October 9th, 2018)
Version 3.0.0 (October 3rd, 2018)
Version 2.1.4 (August 16th, 2018)
Version 2.1.3 (March 5th, 2018)
Version 2.1.2 (December 7th, 2017)
Version 2.1.1 (October 2nd, 2017)
Version 2.1 (September 28th, 2017)
Version 2.0 (March 8th, 2017)
Version 1.5 (November 4th, 2016)
Version 1.4.3 (May 23rd, 2016)
Version 1.4.2 (September 11, 2015)
Version 1.4.1 (December 15, 2014)
Version 1.4 (January 12, 2014)
Version 1.3
Version 1.2.2 (May 18, 2013)
Version 1.2.1 (February 19, 2013)
Version 1.2 (January 28, 2013)
Version 1.1.5
Version 1.1.4
Version 1.1.3 (July 10, 2012)
Version 1.1.2 (June 1, 2012)
Version 1.1.1 (February 17, 2012)
Version 1.1.0 (October 24, 2011)
Version 1.0.4 (September 2, 2011)
Version 1.0.3 (June 14, 2011)
Version 1.0.2 (June 6, 2011)
Version 1.0.1 (April 12, 2011)
Migrating from the html5lib sanitizer
Documentation overview
Previous: Bleach development
Next: Migrating from the html5lib sanitizer
©2012-2015, James Socol; 2015-2017, Mozilla Foundation.
| Powered by Sphinx 7.4.4 & Alabaster 0.7.16 | Page source
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →