PT-2026-40360 · Nanazip · Nanazip

·

CVE-2026-42446

·

Published

2026-05-12

·

Updated

2026-05-12

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions NanaZip versions 5.0.1252.0 through 6.0.1697.0
Description A stack-based out-of-bounds read exists in the ZealFS filesystem image parser. This occurs when opening a specially crafted ZealFS v1 filesystem image, where an attacker-controlled BitmapSize field in the file header triggers an unbounded loop that reads past the end of a stack-allocated ZEALFS V1 HEADER structure.
Recommendations Update to version 6.0.1698.0.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42446
GHSA-4C79-HFR4-MQV9

Affected Products

Nanazip