PT-2026-4869 · Unknown+1 · Tildearrow Furnace+1

Titan Team

·

Published

2026-01-27

·

Updated

2026-01-27

·

CVE-2026-24800

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Red
Name of the Vulnerable Software and Affected Versions tildearrow furnace (affected versions not specified)
Description An out-of-bounds write issue, specifically a buffer copy without checking the size of the input ('Classic Buffer Overflow'), exists in the furnace software within the extern/zlib modules, specifically in the inflate.C file. This condition can lead to remote code execution without requiring user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-77997
AZL-78003
AZL-78006
AZL-78047
CVE-2026-24800

Affected Products

Tildearrow Furnace
Zlib