CVE-2025-6497: HTACG tidy-html5 parser.c prvTidyParseNamespace assertion
Published Jun 23, 2025
·Updated
A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The manipulation leads to reachable assertion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
HTACG tidy-html5
Event History
Jun 23, 2025
CVE Published
via MITRE·12:31 AM
Data Sourced
via MITRE·12:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Jul 1, 57463
Event
via FIRST·01:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6497?
CVE-2025-6497 has been rated as problematic.
2
What component of HTACG tidy-html5 is affected by CVE-2025-6497?
CVE-2025-6497 affects the function prvTidyParseNamespace in the file src/parser.c.
3
Can CVE-2025-6497 be exploited remotely?
No, CVE-2025-6497 requires local exploitation.
4
What type of vulnerability is CVE-2025-6497?
CVE-2025-6497 is characterized by a reachable assertion leading to potential manipulation.
5
How can I mitigate CVE-2025-6497 in HTACG tidy-html5?
Mitigation for CVE-2025-6497 typically involves updating to a patched version of HTACG tidy-html5.