Vulnerability Description
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| M2Team | Nanazip | >= 5.0.1252.0, < 6.0.1630.0 |
Related Weaknesses (CWE)
References
- https://github.com/M2Team/NanaZip/security/advisories/GHSA-ccpc-2222-xv5cExploitThird Party Advisory
- https://github.com/user-attachments/files/25274143/poc.exe.zipExploit
FAQ
What is CVE-2026-26282?
CVE-2026-26282 is a vulnerability with a CVSS score of 6.6 (MEDIUM). NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing ...
How severe is CVE-2026-26282?
CVE-2026-26282 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-26282?
Check the references section above for vendor advisories and patch information. Affected products include: M2Team Nanazip.