What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

x3Cbx3Ex3C decodes to <b><—but only in a context that recognizes backslash-x hexadecimal escapes, such as a JavaScript or Python string literal. The b is ordinary text between two escapes. This is not, by itself, HTML entity encoding, URL encoding, or valid standard JSON escape syntax.

Decode the sequence one piece at a time

Read each xHH as a backslash, the letter x, and exactly two hexadecimal digits when the relevant parser supports that escape:

Source fragment Meaning Result
x3C Hexadecimal value 0x3C <
b Literal character b
x3E Hexadecimal value 0x3E >
x3C Hexadecimal value 0x3C <

The resulting four characters are:

<b><

The escape consumes only 3C after the first x; it does not consume the following b. So this is not an encoded complete <b> tag. It is an opening b tag followed by another less-than sign, an incomplete fragment of markup.

Why do 3C and 3E become angle brackets?

Hexadecimal is base 16, using digits 0–9 and letters A–F. The values 0x3C and 0x3E correspond to Unicode characters U+003C LESS-THAN SIGN and U+003E GREATER-THAN SIGN. They are decimal 60 and 62, respectively.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That does not make x3C a universal character encoding. It is a particular escape notation interpreted by a language or parser. For ASCII characters such as these, the hexadecimal value also matches the UTF-8 byte value, but that coincidence should not be generalized to every character: an escape spelling, a Unicode code point, and a byte serialization are different layers.

Which syntax is it? Compare the common forms

Representation of < Typical context How it differs
x3C JavaScript and Python string escapes; some other language or regex syntaxes Backslash followed by x and two hex digits in JavaScript strings.
u003C JavaScript strings and JSON strings A Unicode escape with four hex digits.
&#x3C; HTML source An HTML hexadecimal character reference.
&lt; HTML source An HTML named character reference.
%3C URLs and URI components Percent-encoding, not backslash escaping.
3C CSS A CSS escape with CSS-specific parsing rules.

For the angle brackets, HTML references such as &#x3C; and &lt; can represent the same character as x3C does in a JavaScript string. But the spellings belong to different grammars and require different decoders. See MDN’s guides to HTML character references and escape characters for the distinction.

What happens in JavaScript?

JavaScript string literals recognize x followed by exactly two hexadecimal digits. In source code, the sequence below is parsed as a string value:

const value = "x3Cbx3Ex3C";
console.log(value);        // <b><
console.log(value.length); // 4

The equivalent value written without escapes is "<b><". MDN documents the JavaScript string-literal escape rules.

There is an important source-versus-data distinction. If the characters x3Cbx3Ex3C arrive from an API or appear in a text file, they are just characters unless your program explicitly decodes them. A JavaScript literal and a string containing the literal backslash sequence are not the same:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
"x3C"   // JavaScript source produces: <
"\x3C" // JavaScript source produces the literal text: x3C

In a regular expression, JavaScript also supports xHH escapes, but the regular-expression parser is a separate context. For example, /x3C/.test("<") is true. When constructing a regex from a string, remember that the JavaScript string parser runs first: new RegExp("\x3C") passes the regex parser the characters x3C, while new RegExp("x3C") passes it an already-decoded <. See MDN’s reference for JavaScript regular-expression character escapes.

What happens in Python?

Python string literals also interpret xHH escapes:

value = "x3Cbx3Ex3C"
print(value)  # <b><

If your Python program receives the backslashes as literal input and you want to preserve them initially, use a raw string or double each backslash:

raw = r"x3Cbx3Ex3C"
# or: raw = "\x3Cb\x3E\x3C"

For a known input that needs only these two-digit hexadecimal escapes interpreted, a narrow replacement is clearer and safer than evaluating text or applying a broad escape decoder:

import re

def decode_hex_escapes(value):
    return re.sub(
        r"\x([0-9A-Fa-f]{2})",
        lambda match: chr(int(match.group(1), 16)),
        value,
    )

print(decode_hex_escapes(r"x3Cbx3Ex3C"))  # <b><

Python’s html.unescape() is for HTML character references such as &#x3E;, not JavaScript-style backslash escapes. The Python HTML utilities documentation describes that separate job.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why it is not valid standard JSON

JSON strings support escapes such as ", \, n, and uXXXX; JSON does not define JavaScript-style xHH. A conforming JSON parser should reject this:

{"value":"x3Cbx3Ex3C"}

To represent the decoded angle brackets in valid JSON, use Unicode escapes:

{"value":"u003Cbu003Eu003C"}

That JSON parses to the value <b><. If instead you want JSON to carry the literal backslash sequence as data, escape each backslash in JSON:

{"value":"\x3Cb\x3E\x3C"}

After JSON parsing, the value is the literal text x3Cbx3Ex3C; JSON has not performed a second, JavaScript-style decoding step. RFC 8259 specifies the JSON string escape grammar and the use of UTF-8 for JSON exchanged between systems.

Why it is not HTML or URL encoding

An ordinary HTML parser does not treat a backslash followed by x3C as an HTML character reference. In normal HTML text, this markup displays the backslashes literally:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
<p>x3Cbx3Ex3C</p>

By contrast, these HTML forms represent the angle brackets as text:

<p>&lt;b&gt;&lt;</p>
<p>&#x3C;b&#x3E;&#x3C;</p>

URL percent-encoding uses percent signs: %3Cb%3E%3C. A URL decoder may turn that form into <b><; it will not decode x3Cbx3Ex3C. Conversely, a JavaScript escape decoder should not be applied to arbitrary URL data. Use the decoder for the syntax actually present.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Decode literal input without executing it

If the input is a string containing the literal backslashes, decode only the documented pattern you intend to support. In JavaScript:

function decodeHexEscapes(input) {
  return input.replace(/\x([0-9A-Fa-f]{2})/g, (_, hex) =>
    String.fromCharCode(parseInt(hex, 16))
  );
}

const input = String.raw`x3Cbx3Ex3C`;
console.log(decodeHexEscapes(input)); // <b><

This transforms only backslash-x plus two hex digits. It does not interpret arbitrary JavaScript, Unicode escapes, or other backslash conventions. Do not use eval() to decode a string: evaluation can run code and is unnecessary for this transformation. Likewise, avoid passing untrusted strings to shell evaluation or Python’s eval().

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Decoding is not sanitizing

The decoded result is only <b><, an incomplete markup fragment—not a complete executable payload. Still, in security logs or suspicious input, escaped characters can conceal syntax from a casual reader or a simplistic filter. Decoding reveals characters; it does not establish that the result is safe.

Whether a string is treated as markup depends on how it is used. In a browser, putting a value in textContent displays it as text, while assigning it to innerHTML asks the browser to parse it as HTML:

element.textContent = value; // text, not parsed as HTML
element.innerHTML = value;   // parsed as HTML

Do not decode a value and then place it into an HTML parser, attribute, script, CSS, URL, or shell context without handling that destination appropriately. The correct defense depends on the output context; encoding for one context is not automatically safe in another. OWASP explains this in its guidance on cross-site scripting prevention and encoded injection. For displaying untrusted text in a web page, prefer a text API such as textContent rather than parsing it as HTML.

Quick troubleshooting checklist

  1. Identify the context. Is this JavaScript source, Python source, JSON, HTML, a URL, CSS, a regex, or plain text?
  2. Check whether the backslashes are literal. A parser may already have converted an escape before you inspect the resulting value.
  3. Choose the matching decoder. x3C, u003C, &#x3C;, and %3C are not interchangeable.
  4. Decide whether you need text or markup. A string containing angle brackets is not automatically parsed by a browser.
  5. Keep the transformation narrow. Do not evaluate data to decode it, and do not assume decoding makes it safe for its destination.

In short: x3Cbx3Ex3C means <b>< when a compatible escape parser reads it. Elsewhere, it may remain literal text or be invalid. The notation—not just the characters—tells you which interpretation applies.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.