VYPR
Medium severity6.1NVD Advisory· Published Feb 22, 2017· Updated Jun 17, 2026

CVE-2016-9909

CVE-2016-9909

Description

The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
html5libPyPI
< 0.9999999990.999999999

Affected products

2

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.