What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
x3Cbx3Ex3C decodes to <b><—but only in a context that recognizes backslash-x hexadecimal escapes, such as a JavaScript or Python string literal. The b is ordinary text between two escapes. This is not, by itself, HTML entity encoding, URL encoding, or valid standard JSON escape syntax.
Decode the sequence one piece at a time
Read each xHH as a backslash, the letter x, and exactly two hexadecimal digits when the relevant parser supports that escape:
| Source fragment | Meaning | Result |
|---|---|---|
x3C |
Hexadecimal value 0x3C |
< |
b |
Literal character | b |
x3E |
Hexadecimal value 0x3E |
> |
x3C |
Hexadecimal value 0x3C |
< |
The resulting four characters are:
<b><
The escape consumes only 3C after the first x; it does not consume the following b. So this is not an encoded complete <b> tag. It is an opening b tag followed by another less-than sign, an incomplete fragment of markup.
Why do 3C and 3E become angle brackets?
Hexadecimal is base 16, using digits 0–9 and letters A–F. The values 0x3C and 0x3E correspond to Unicode characters U+003C LESS-THAN SIGN and U+003E GREATER-THAN SIGN. They are decimal 60 and 62, respectively.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallThat does not make x3C a universal character encoding. It is a particular escape notation interpreted by a language or parser. For ASCII characters such as these, the hexadecimal value also matches the UTF-8 byte value, but that coincidence should not be generalized to every character: an escape spelling, a Unicode code point, and a byte serialization are different layers.
Which syntax is it? Compare the common forms
Representation of < |
Typical context | How it differs |
|---|---|---|
x3C |
JavaScript and Python string escapes; some other language or regex syntaxes | Backslash followed by x and two hex digits in JavaScript strings. |
u003C |
JavaScript strings and JSON strings | A Unicode escape with four hex digits. |
< |
HTML source | An HTML hexadecimal character reference. |
< |
HTML source | An HTML named character reference. |
%3C |
URLs and URI components | Percent-encoding, not backslash escaping. |
3C |
CSS | A CSS escape with CSS-specific parsing rules. |
For the angle brackets, HTML references such as < and < can represent the same character as x3C does in a JavaScript string. But the spellings belong to different grammars and require different decoders. See MDN’s guides to HTML character references and escape characters for the distinction.
What happens in JavaScript?
JavaScript string literals recognize x followed by exactly two hexadecimal digits. In source code, the sequence below is parsed as a string value:
const value = "x3Cbx3Ex3C";
console.log(value); // <b><
console.log(value.length); // 4
The equivalent value written without escapes is "<b><". MDN documents the JavaScript string-literal escape rules.
There is an important source-versus-data distinction. If the characters x3Cbx3Ex3C arrive from an API or appear in a text file, they are just characters unless your program explicitly decodes them. A JavaScript literal and a string containing the literal backslash sequence are not the same:
Rank #2
"x3C" // JavaScript source produces: <
"\x3C" // JavaScript source produces the literal text: x3C
In a regular expression, JavaScript also supports xHH escapes, but the regular-expression parser is a separate context. For example, /x3C/.test("<") is true. When constructing a regex from a string, remember that the JavaScript string parser runs first: new RegExp("\x3C") passes the regex parser the characters x3C, while new RegExp("x3C") passes it an already-decoded <. See MDN’s reference for JavaScript regular-expression character escapes.
What happens in Python?
Python string literals also interpret xHH escapes:
value = "x3Cbx3Ex3C"
print(value) # <b><
If your Python program receives the backslashes as literal input and you want to preserve them initially, use a raw string or double each backslash:
raw = r"x3Cbx3Ex3C"
# or: raw = "\x3Cb\x3E\x3C"
For a known input that needs only these two-digit hexadecimal escapes interpreted, a narrow replacement is clearer and safer than evaluating text or applying a broad escape decoder:
import re
def decode_hex_escapes(value):
return re.sub(
r"\x([0-9A-Fa-f]{2})",
lambda match: chr(int(match.group(1), 16)),
value,
)
print(decode_hex_escapes(r"x3Cbx3Ex3C")) # <b><
Python’s html.unescape() is for HTML character references such as >, not JavaScript-style backslash escapes. The Python HTML utilities documentation describes that separate job.
Why it is not valid standard JSON
JSON strings support escapes such as ", \, n, and uXXXX; JSON does not define JavaScript-style xHH. A conforming JSON parser should reject this:
{"value":"x3Cbx3Ex3C"}
To represent the decoded angle brackets in valid JSON, use Unicode escapes:
Rank #4
{"value":"u003Cbu003Eu003C"}
That JSON parses to the value <b><. If instead you want JSON to carry the literal backslash sequence as data, escape each backslash in JSON:
{"value":"\x3Cb\x3E\x3C"}
After JSON parsing, the value is the literal text x3Cbx3Ex3C; JSON has not performed a second, JavaScript-style decoding step. RFC 8259 specifies the JSON string escape grammar and the use of UTF-8 for JSON exchanged between systems.
Why it is not HTML or URL encoding
An ordinary HTML parser does not treat a backslash followed by x3C as an HTML character reference. In normal HTML text, this markup displays the backslashes literally:
<p>x3Cbx3Ex3C</p>
By contrast, these HTML forms represent the angle brackets as text:
Best Value
<p><b><</p>
<p><b><</p>
URL percent-encoding uses percent signs: %3Cb%3E%3C. A URL decoder may turn that form into <b><; it will not decode x3Cbx3Ex3C. Conversely, a JavaScript escape decoder should not be applied to arbitrary URL data. Use the decoder for the syntax actually present.
Decode literal input without executing it
If the input is a string containing the literal backslashes, decode only the documented pattern you intend to support. In JavaScript:
function decodeHexEscapes(input) {
return input.replace(/\x([0-9A-Fa-f]{2})/g, (_, hex) =>
String.fromCharCode(parseInt(hex, 16))
);
}
const input = String.raw`x3Cbx3Ex3C`;
console.log(decodeHexEscapes(input)); // <b><
This transforms only backslash-x plus two hex digits. It does not interpret arbitrary JavaScript, Unicode escapes, or other backslash conventions. Do not use eval() to decode a string: evaluation can run code and is unnecessary for this transformation. Likewise, avoid passing untrusted strings to shell evaluation or Python’s eval().
Recommended Free Tools
Decoding is not sanitizing
The decoded result is only <b><, an incomplete markup fragment—not a complete executable payload. Still, in security logs or suspicious input, escaped characters can conceal syntax from a casual reader or a simplistic filter. Decoding reveals characters; it does not establish that the result is safe.
Whether a string is treated as markup depends on how it is used. In a browser, putting a value in textContent displays it as text, while assigning it to innerHTML asks the browser to parse it as HTML:
element.textContent = value; // text, not parsed as HTML
element.innerHTML = value; // parsed as HTML
Do not decode a value and then place it into an HTML parser, attribute, script, CSS, URL, or shell context without handling that destination appropriately. The correct defense depends on the output context; encoding for one context is not automatically safe in another. OWASP explains this in its guidance on cross-site scripting prevention and encoded injection. For displaying untrusted text in a web page, prefer a text API such as textContent rather than parsing it as HTML.
Quick Recap
Quick troubleshooting checklist
- Identify the context. Is this JavaScript source, Python source, JSON, HTML, a URL, CSS, a regex, or plain text?
- Check whether the backslashes are literal. A parser may already have converted an escape before you inspect the resulting value.
- Choose the matching decoder.
x3C,u003C,<, and%3Care not interchangeable. - Decide whether you need text or markup. A string containing angle brackets is not automatically parsed by a browser.
- Keep the transformation narrow. Do not evaluate data to decode it, and do not assume decoding makes it safe for its destination.
In short: x3Cbx3Ex3C means <b>< when a compatible escape parser reads it. Elsewhere, it may remain literal text or be invalid. The notation—not just the characters—tells you which interpretation applies.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

