CVE-2025-6496: HTACG tidy-html5 parser.c InsertNodeAsParent null pointer dereference
Published Jun 23, 2025
·Updated
A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the function InsertNodeAsParent of the file src/parser.c. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
HTACG tidy-html5
Event History
Jun 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Jun 13, 58473
Event
via NVD·11:54 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-6496?
CVE-2025-6496 has been declared as problematic due to its potential for null pointer dereference.
2
How do I fix CVE-2025-6496?
To mitigate CVE-2025-6496, you should update to a patched version of HTACG tidy-html5 when it becomes available.
3
What is affected by CVE-2025-6496?
CVE-2025-6496 affects the HTACG tidy-html5 version 5.8.0.
4
What type of access is required for CVE-2025-6496 exploitation?
CVE-2025-6496 requires local access to exploit the vulnerability.
5
What function is involved in CVE-2025-6496?
CVE-2025-6496 involves the InsertNodeAsParent function in the src/parser.c file.