CVE-2025-6498
LOWHtacg Tidy - Memory Leak
Title source: ruleDescription
A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
References (5)
Scores
CVSS v3
3.3
EPSS
0.0004
EPSS Percentile
13.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Classification
CWE
CWE-401
CWE-404
Status
published
Affected Products (1)
htacg/tidy
Timeline
Published
Jun 23, 2025
Tracked Since
Feb 18, 2026