CVE-2025-6490 describes a problematic heap-based buffer overflow vulnerability within the hashmap_set_with_hash function of the gumbo-parser/src/hashmap.c file in the sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 component. This vulnerability is rated as Low severity (CVSS 3.3), requiring local access and low privileges for exploitation, with a potential impact of low availability. While a patch exists (ada4708e5a67114402cd3feb70a4e1d1d7cf773a), the affected code was never part of an official release, and its real existence is currently doubted. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sparklemotion | Nokogiri | c29c920907366cb74af13b4dc2230e9c9e23b833CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.