PT-2025-26576 · Htacg+1 · Tidy-Html5+1

Jjleo

·

Published

2025-06-23

·

Updated

2025-06-23

·

CVE-2025-6498

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: HTACG tidy-html5 version 5.8.0
Description: A memory leak issue has been discovered, affecting the defaultAlloc function in the src/alloc.c file. This issue can be exploited locally, potentially leading to memory leak. The exploit details have been publicly disclosed.
Recommendations: For HTACG tidy-html5 version 5.8.0, consider restricting access to the defaultAlloc function in the src/alloc.c file as a temporary mitigation measure until a patch is available.

Exploit

Fix

Improper Resource Release

Memory Leak

Weakness Enumeration

Related Identifiers

AZL-64314
AZL-64320
CVE-2025-6498

Affected Products

Debian
Tidy-Html5