CVE-2017-13692: Htacg Tidy

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.

Affected products

  • Htacg Tidy: version 5.5.31 only

Published 2017-08-25. Last modified 2026-06-17.