cbcvebase.

M2Team Nanazip vulnerabilities

21 known vulnerabilities affecting m2team/nanazip.

Total CVEs
21
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM13LOW4

Vulnerabilities

Page 1 of 2
CVE-2026-27114P3HIGHCVSS 7.5≥ 5.0.1252.0, < 6.0.1630.0v>= 5.0.1252.0, < 6.0.1630.02026-02-19
CVE-2026-27114 [HIGH] CWE-835 CVE-2026-27114: NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630 NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
nvd
CVE-2026-55780P4LOWCVSS 2.4PoCfixed in 6.5.1749.02026-07-10
CVE-2026-55780 [LOW] CWE-248 CVE-2026-55780: NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, Nan NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp sizes its extraction buffer from the bundle entry Size field, which is only checked for sign and is not validated against the real file size. A crafted bundle can cause
nvd
CVE-2026-54616P3HIGHCVSS 7.1v>= 1.0.88.0, < 6.0.1698.0v>= 6.5.1638.0, < 6.5.1742.02026-08-20
CVE-2026-54616 [HIGH] CWE-125 CVE-2026-54616: NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 un NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rejects only a zero return from LZ4_decompress_safe even though malformed input produces a negative error
nvd
CVE-2026-44215P3HIGHCVSS 7.1≥ 5.0.1252.0, < 6.0.1698.0v>= 5.0.1250.0, < 6.0.1698.02026-05-12
CVE-2026-44215 [HIGH] CWE-787 CVE-2026-44215: NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS filesystem image. The attacker controls the byte offset of the write within a ~254-byte window past the heap allocati
nvd
CVE-2026-42446P4HIGHCVSS 7.1≥ 5.0.1252.0, < 6.0.1698.0v>= 5.0.1250.0, < 6.0.1698.02026-05-12
CVE-2026-42446 [HIGH] CWE-125 CVE-2026-42446: NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-b NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted ZealFS v1 filesystem image. An attacker-controlled BitmapSize field in the file header drives an unbounded loop that reads past the
nvd
CVE-2026-26282P4MEDIUMCVSS 6.6≥ 5.0.1252.0, < 6.0.1630.0v>= 5.0.1252.0, < 6.0.1630.02026-02-19
CVE-2026-26282 [MEDIUM] CWE-126 CVE-2026-26282: NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630. NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.
nvd
CVE-2026-27711P4MEDIUMCVSS 6.6≥ 5.0.1252.0, < 6.0.1638.0v>= 5.0.1252.0, < 6.0.1638.0+1 more2026-02-26
CVE-2026-27711 [MEDIUM] CWE-125 CVE-2026-27711: NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.163 NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser allows a crafted `.ufs/.ufs2/.img` file to trigger out-of-bounds memory access during archive open/listing. The bug is reachable via normal user file-open flow and can cause
nvd
CVE-2026-27709P4MEDIUMCVSS 6.6≥ 5.0.1252.0, < 6.0.1638.0v>= 5.0.1252.0, < 6.0.1638.0+1 more2026-02-26
CVE-2026-27709 [MEDIUM] CWE-125 CVE-2026-27709: NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.163 NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-of-bounds read vulnerability in manifest parsing. A crafted bundle can provide a malformed `RelativePathLength` so the parser constructs a `std::string` from memory beyond
nvd
CVE-2026-47223P4MEDIUMCVSS 5.4v>= 3.0.1000.0, < 6.0.1698.02026-06-12
CVE-2026-47223 [MEDIUM] CWE-125 CVE-2026-47223: NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Zip AvbHandler). A 32-bit unsigned integer overflow in the bounds check pos + ht.salt_len > descSize al
nvd
CVE-2026-47222P4MEDIUMCVSS 5.4v>= 3.0.1000.0, < 6.0.1698.02026-06-12
CVE-2026-47222 [MEDIUM] CWE-125 CVE-2026-47222: NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the Android Verified Boot (AVB) vbmeta image parser in NanaZip (via the upstream 7-Zip AvbHandler). An unsigned integer underflow in a bounds check allows an attacker-controlled value_nu
nvd
CVE-2026-42445P4MEDIUMCVSS 5.5≥ 5.0.1252.0, < 6.0.1698.0v>= 5.0.1250.0, < 6.0.1698.02026-05-12
CVE-2026-42445 [MEDIUM] CWE-674 CVE-2026-42445: NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recurs NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPaths recurses into subdirectories without any depth limit or visited-inode tracking. A crafted UFS image with a deep directory tree or an inode cycle caus
nvd
CVE-2026-42355P4MEDIUMCVSS 5.5≥ 5.0.1250.0, < 6.0.1698.0v>= 5.0.1250.0, < 6.0.1698.02026-05-12
CVE-2026-42355 [MEDIUM] CWE-674 CVE-2026-42355: NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recurs NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and the handler's GetAllPaths function recurse without depth limits, exhaust
nvd
CVE-2026-42442P4MEDIUMCVSS 5.5≥ 5.0.1250.0, < 6.0.1698.0v>= 5.0.1250.0, < 6.0.1698.02026-05-12
CVE-2026-42442 [MEDIUM] CWE-476 CVE-2026-42442: NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer derefer NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the root inode (inode 2) is set to IFLNK (symlink) instead of IFDIR (directory). The parser unconditionally treats th
nvd
CVE-2026-42444P4MEDIUMCVSS 5.5≥ 5.0.1252.0, < 6.0.1698.0v>= 5.0.1250.0, < 6.0.1698.02026-05-12
CVE-2026-42444 [MEDIUM] CWE-770 CVE-2026-42444: NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vu NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handler's Open method reads BlockCount directly from the attacker-controlled superblock without any validation against the actual file size or any upper-bound ceiling, then ite
nvd
CVE-2026-42443P4MEDIUMCVSS 5.5≥ 5.0.1252.0, < 6.0.1698.0v>= 5.0.1250.0, < 6.0.1698.02026-05-12
CVE-2026-42443 [MEDIUM] CWE-369 CVE-2026-42443: NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-z NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability is triggered when opening a crafted UFS image where the superblock field fs_ipg (inodes per cylinder group) is set to zero. The parser uses this attacker-controlled value
nvd
CVE-2026-27014P4MEDIUMCVSS 5.5≥ 5.0.1252.0, < 6.0.1630.0v>= 5.0.1252.0, < 6.0.1630.02026-02-19
CVE-2026-27014 [MEDIUM] CWE-674 CVE-2026-27014: NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630. NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
nvd
CVE-2026-47224P4MEDIUMCVSS 4.3v>= 3.0.1000.0, < 6.0.1698.02026-06-12
CVE-2026-47224 [MEDIUM] CWE-125 CVE-2026-47224: NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap buffer-overflow read exists in the LVM2 physical-volume metadata parser in NanaZip (via the upstream 7-Zip LvmHandler). The vulnerability is triggered when opening a crafted LVM disk image. This issue has been patch
nvd
CVE-2026-27710P4MEDIUMCVSS 5.0≥ 5.0.1252.0, < 6.0.1638.0v>= 5.0.1252.0, < 6.0.1638.0+1 more2026-02-26
CVE-2026-27710 [MEDIUM] CWE-191 CVE-2026-27710: NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.163 NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Application` parser. A crafted bundle can force an integer underflow in header-size calculation and trigger an unbounded memory allocation attempt during archi
nvd
CVE-2026-55781P4LOWCVSS 2.4fixed in 6.5.1749.02026-07-10
CVE-2026-55781 [LOW] CWE-400 CVE-2026-55781: NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, Nan NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS image handler in NanaZip.Codecs.Archive.Ufs.cpp validates the superblock block size only against the MINBSIZE lower bound and does not validate the fs_fsize fragment size, allowing attacker-controlled 32-bit fields to flow into indirec
nvd
CVE-2026-55782P4LOWCVSS 2.4fixed in 6.5.1749.02026-07-10
CVE-2026-55782 [LOW] CWE-400 CVE-2026-55782: NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, Nan NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in the file. A tiny crafted module can f
nvd
M2Team Nanazip vulnerabilities | cvebase