CVE-2026-55782
published 2026-07-10CVE-2026-55782: NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in…
PriorityP411low2.4CVSS 4.0
AVLACLATNPRLUIPVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.11%
1.7th percentile
NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in the file. A tiny crafted module can force multi-gigabyte allocations during listing or extraction through NameSize, Information.Size, and std::string or vector allocation paths, causing memory exhaustion or process termination. This issue is fixed in version 6.5.1749.0.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| m2team | nanazip | < 6.5.1749.0 | 6.5.1749.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/M2Team/NanaZip/commit/1ce90f2d14a984476d0407a835273705607facf2https://github.com/M2Team/NanaZip/commit/56aee89037947410dd5e66f3a087e0f290484baehttps://github.com/M2Team/NanaZip/commit/92b12a6e1eb0cf8e88fcc277aa7508ca1ff27db6https://github.com/M2Team/NanaZip/releases/tag/6.5.1749.0https://github.com/M2Team/NanaZip/security/advisories/GHSA-qxhc-2v6p-wm8mhttps://github.com/M2Team/NanaZip/security/advisories/GHSA-qxhc-2v6p-wm8m
2026-07-10
Published