CNNVD-202506-2929 Information

CNNVD ID

CNNVD-202506-2929

CVE-2025-6497

  • CNNVD Published: 2025-06-23

Description (Chinese)

HTACG HTML Tidy是HTML Tidy Advocacy Community Group开源的一个 HTML 工具。 HTACG HTML Tidy 5.8.0版本存在安全漏洞,该漏洞源于src/parser.c文件中prvTidyParseNamespace函数存在可达断言问题。

Description (English)

HTACG HTML Tidy is an HTML open-source HTML tool. There is a security loophole in version 5.8.0 of HTACG HTML Tidy, which arises from the prvTidyParseNamespace function in src/parser.c.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

HTML Tidy Advocacy Community Group

Published

2025-06-23

Last Modified

2026-02-24

References

https://github.com/htacg/tidy-html5/issues/1142 https://github.com/user-attachments/files/19825297/tidy-html5_crash_2.txt https://vuldb.com/?id.313613 https://vuldb.com/?submit.601008 https://vuldb.com/?ctiid.313613 https://access.redhat.com/security/cve/cve-2025-6497

Patch

https://github.com/htacg/tidy-html5/releases

Share on: