Htacg maintains Tidy, a widely embedded HTML parser and sanitizer that is deployed across web servers, content management systems, and document-processing tools despite its narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity; the recurring weakness classes—including buffer-bounds violations, input-validation gaps, resource-management errors, and use-after-free conditions—reflect the memory-safety demands inherent to a C-based parser that handles untrusted markup. Defenders should prioritize patching Tidy instances in internet-facing services and verify downstream product updates, since a single flaw in a widely embedded library can propagate broadly; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Htacg over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33391CRITICAL An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c. | Feb 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-13692HIGH In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument. | Aug 25, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-17497HIGH In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children | Dec 10, 2017 | 7.5 | 24 | NO | NO |
CVE-2015-5522MEDIUM Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command | Aug 11, 2015 | 6.8 | 19 | NO | NO |
CVE-2025-6498MEDIUM A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. Affected is the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory | Jun 23, 2025 | 5.5 | 17 | NO | NO |
CVE-2015-5523MEDIUM The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an | Aug 11, 2015 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Htacg.
Media articles that mention a CVE ID that affects a product developed by Htacg — matched by CVE ID, not by vendor name.