Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-6490

15
FAUCET Score

CVE-2025-6490 describes a problematic heap-based buffer overflow vulnerability within the hashmap_set_with_hash function of the gumbo-parser/src/hashmap.c file in the sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 component. This vulnerability is rated as Low severity (CVSS 3.3), requiring local access and low privileges for exploitation, with a potential impact of low availability. While a patch exists (ada4708e5a67114402cd3feb70a4e1d1d7cf773a), the affected code was never part of an official release, and its real existence is currently doubted. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
SparklemotionNokogiri
c29c920907366cb74af13b4dc2230e9c9e23b833CNA affected

CVSS Data

CVSS version used by this source: 4.0

1.9LOW

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
5.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 35th percentile among its peer group of 1,511 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

rubygemsGHSA-pf9w-gvcf-gv7mlow

sparklemotion nokogiri hashmap.c hashmap_set_with_hash heap-based overflow

Jun 22, 2025

References

github.com / sparklemotion/nokogiri/commit/ada4708e5a67114402cd3feb70a4e1d1d7cf773a
github.com / sparklemotion/nokogiri/issues/3500
github.com / sparklemotion/nokogiri/pull/3524
github.com / user-attachments/files/19625432/nokogiri_crash.txt
vuldb.com
vuldb.com
vuldb.com