A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to an incomplete fix of CVE-2022-1211. It is possible to initiate the attack remotely but it requires user interaction. The issue got fixed with the patch 0eb02422d5161767e9983bdaa5c429762d3477ce.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "0.2"
},
{
"introduced": "0"
},
{
"last_affected": "0.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "0.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "0.3"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "0.4"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.4"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.5"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.5-real"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.6"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.7"
},
{
"introduced": "0"
},
{
"last_affected": "0.5"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.5"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.6"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.7-NA"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.7-pre4"
},
{
"introduced": "0"
},
{
"last_affected": "0.5.8"
},
{
"introduced": "0"
},
{
"last_affected": "0.6-pre0"
},
{
"introduced": "0"
},
{
"last_affected": "dev5"
},
{
"introduced": "0"
},
{
"last_affected": "dev6"
},
{
"introduced": "0"
},
{
"last_affected": "dev7"
},
{
"introduced": "0"
},
{
"last_affected": "dev8"
},
{
"introduced": "0"
},
{
"last_affected": "dev9"
},
{
"introduced": "0"
},
{
"last_affected": "dev10"
},
{
"introduced": "0"
},
{
"last_affected": "dev62"
},
{
"introduced": "0"
},
{
"last_affected": "dev63"
},
{
"introduced": "0"
},
{
"last_affected": "dev64"
},
{
"introduced": "0"
},
{
"last_affected": "dev65"
},
{
"introduced": "0"
},
{
"last_affected": "dev66"
},
{
"introduced": "0"
},
{
"last_affected": "dev67"
},
{
"introduced": "0"
},
{
"last_affected": "dev68"
},
{
"introduced": "0"
},
{
"last_affected": "dev69"
},
{
"introduced": "0"
},
{
"last_affected": "dev70"
},
{
"introduced": "0"
},
{
"last_affected": "dev71"
},
{
"introduced": "0"
},
{
"last_affected": "dev72"
},
{
"introduced": "0"
},
{
"last_affected": "dev73"
},
{
"introduced": "0"
},
{
"last_affected": "dev75"
},
{
"introduced": "0"
},
{
"last_affected": "dev76"
},
{
"introduced": "0"
},
{
"last_affected": "dev77"
},
{
"introduced": "0"
},
{
"last_affected": "dev78"
},
{
"introduced": "0"
},
{
"last_affected": "dev79"
},
{
"introduced": "0"
},
{
"last_affected": "dev80"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1289.json"
"2026-04-11T23:42:01Z"
[
{
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/tildearrow/furnace/commit/0eb02422d5161767e9983bdaa5c429762d3477ce",
"digest": {
"threshold": 0.9,
"line_hashes": [
"335054832721819695341258929487485254091",
"188167164482528443823020661433853272003",
"275695170689737141780568725748329210444",
"229775994306794305861732485281585947710",
"205542306335405924399593836027670631170",
"5527374082439882929407294290345732572",
"14205804872781347412031128190549890686",
"224527381082166424050347205262292829280",
"299615791772188005475367469667676677627",
"35291682120878028074562167328046806675",
"229305566675741677860294076858399250525",
"191678615460417363471654598511070760145",
"94755691338511321975974293456769700443",
"338229083817740201723464914651087997401",
"231427078726831481721968362667948769222",
"180429986184618552289062435907467840408",
"178998884727283178971979818122113358261",
"176855138969740191773339550628523287765",
"292788389037357391129479104853790042689",
"145057607930188924730787717210684651415",
"12026866681922850118580940562993504400",
"138193661692865688140163686713591072773",
"247988030675059336927251877141400701104",
"202937378793698949818660023902147530893"
]
},
"id": "CVE-2022-1289-1ce81ad5",
"deprecated": false,
"target": {
"file": "src/gui/pattern.cpp"
}
},
{
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/tildearrow/furnace/commit/0eb02422d5161767e9983bdaa5c429762d3477ce",
"digest": {
"function_hash": "209561055361738806669877998052791832808",
"length": 12437.0
},
"id": "CVE-2022-1289-b057369c",
"deprecated": false,
"target": {
"file": "src/gui/pattern.cpp",
"function": "FurnaceGUI::patternRow"
}
}
]