Htacg Tidy-Html5 vulnerabilities
5 known vulnerabilities affecting htacg/tidy-html5.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-6498MEDIUMCVSS 4.8v5.8.02025-06-23
CVE-2025-6498 [MEDIUM] CWE-401 CVE-2025-6498: A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the
A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-6496MEDIUMCVSS 4.8v5.8.02025-06-23
CVE-2025-6496 [MEDIUM] CWE-404 CVE-2025-6496: A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulne
A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the function InsertNodeAsParent of the file src/parser.c. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-6497MEDIUMCVSS 4.8v5.8.02025-06-23
CVE-2025-6497 [MEDIUM] CWE-617 CVE-2025-6497: A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue af
A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
nvd
CVE-2021-33391CRITICALCVSS 9.8≥ 0, < 2:5.8.0-22023-02-17
CVE-2021-33391 [CRITICAL] CVE-2021-33391: An issue in HTACG HTML Tidy v5
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
osv
CVE-2017-17497HIGHCVSS 7.5≥ 0, < 2:5.6.0-32017-12-10
CVE-2017-17497 [HIGH] CVE-2017-17497: In Tidy 5
In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.
osv