PT-2026-22043 · Nanazip · Nanazip

Ho-9

·

Publicado

2026-02-25

·

Atualizado

2026-02-26

·

CVE-2026-27709

CVSS v3.1

6.6

Média

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions NanaZip versions 5.0.1252.0 through 6.0.1637.0 and 6.5.1637.0
Description NanaZip, an open source file archive, contains a flaw in its .NET Single File Application parser. Specifically, the parser exhibits an out-of-bounds read condition during manifest parsing. A specially crafted file can provide a malformed RelativePathLength value, causing the parser to construct a std::string using memory beyond the HeaderBuffer. This can lead to a program crash and potential in-process memory disclosure.
Recommendations Update to NanaZip version 6.0.1638.0 or 6.5.1638.0.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27709
GHSA-VR4W-XC78-W6FV

Produtos afetados

Nanazip