Browse all 4 CVE security advisories affecting tildearrow. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Tildearrow is a software component primarily used for data processing and transformation in web applications. Historically, it has been associated with multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues across its CVE history. The component's complex parsing mechanisms and input handling have frequently introduced security weaknesses. While no major public security incidents have been widely documented, its consistent presence in vulnerability reports suggests ongoing challenges in secure coding practices. Organizations using tildearrow should prioritize regular updates and input validation to mitigate risks associated with its historically vulnerable patterns.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-4732 | Out-of-bounds Read Overflow in tildearrow/furnace — furnaceCWE-125 | 7.7 | - | 2026-03-24 |
| CVE-2026-24800 | A heap-based buffer over-read or buffer overflow in tildearrow/furnace — furnaceCWE-787 | 9.8AI | CriticalAI | 2026-01-27 |
| CVE-2022-1289 | tildearrow Furnace Incomplete Fix CVE-2022-1211 denial of service — FurnaceCWE-404 | 4.3 | Medium | 2022-04-10 |
| CVE-2022-1211 | tildearrow Furnace FUR to VGM Converter stack-based overflow — FurnaceCWE-121 | 6.3 | Medium | 2022-04-03 |
This page lists every published CVE security advisory associated with tildearrow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.