CVE-2025-6498

A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:htacg:tidy:5.8.0:*:*:*:*:*:*:*

History

30 Sep 2025, 18:21

Type Values Removed Values Added
First Time Htacg
Htacg tidy
CPE cpe:2.3:a:htacg:tidy:5.8.0:*:*:*:*:*:*:*
References () https://github.com/htacg/tidy-html5/issues/1152 - () https://github.com/htacg/tidy-html5/issues/1152 - Exploit, Issue Tracking
References () https://github.com/user-attachments/files/20438303/tidy-html5_crash_3.txt - () https://github.com/user-attachments/files/20438303/tidy-html5_crash_3.txt - Exploit
References () https://vuldb.com/?ctiid.313614 - () https://vuldb.com/?ctiid.313614 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.313614 - () https://vuldb.com/?id.313614 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.601009 - () https://vuldb.com/?submit.601009 - Third Party Advisory, VDB Entry

23 Jun 2025, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-23 02:15

Updated : 2025-09-30 18:21


NVD link : CVE-2025-6498

Mitre link : CVE-2025-6498

CVE.ORG link : CVE-2025-6498


JSON object : View

Products Affected

htacg

  • tidy
CWE
CWE-401

Missing Release of Memory after Effective Lifetime

CWE-404

Improper Resource Shutdown or Release