Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-64320.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-64320
Upstream
Published
2025-06-23T02:15:20Z
Modified
2026-04-21T04:32:21.861582Z
Summary
CVE-2025-6498 affecting package tidy 5.8.0-6
Details

A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

References

Affected packages

Azure Linux:3 / tidy

Package

Name
tidy
Purl
pkg:rpm/azure-linux/tidy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
5.8.0-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-64320.json"