PT-2026-22043 · Nanazip · Nanazip

Ho-9

·

Published

2026-02-25

·

Updated

2026-02-26

·

CVE-2026-27709

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions NanaZip versions 5.0.1252.0 through 6.0.1637.0 and 6.5.1637.0
Description NanaZip, an open source file archive, contains a flaw in its .NET Single File Application parser. Specifically, the parser exhibits an out-of-bounds read condition during manifest parsing. A specially crafted file can provide a malformed RelativePathLength value, causing the parser to construct a std::string using memory beyond the HeaderBuffer. This can lead to a program crash and potential in-process memory disclosure.
Recommendations Update to NanaZip version 6.0.1638.0 or 6.5.1638.0.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-27709
GHSA-VR4W-XC78-W6FV

Affected Products

Nanazip