CVE-2025-6498

LOW

Htacg Tidy - Memory Leak

Title source: rule

Description

A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 3.3
EPSS 0.0004
EPSS Percentile 13.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Classification

CWE
CWE-401 CWE-404
Status published

Affected Products (1)

htacg/tidy

Timeline

Published Jun 23, 2025
Tracked Since Feb 18, 2026