🔐 CVE Alert

CVE-2026-27710

UNKNOWN 0.0

NanaZip .NET Single-File Parser Integer Underflow Leads to Unbounded Allocation (DoS)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Application` parser. A crafted bundle can force an integer underflow in header-size calculation and trigger an unbounded memory allocation attempt during archive open. Versions 6.0.1638.0 and 6.5.1638.0 fix the issue.

CWE CWE-191
Vendor m2team
Product nanazip
Published Feb 25, 2026
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for m2team nanazip

Be the first to know when new unknown vulnerabilities affecting m2team nanazip are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

M2Team / NanaZip
>= 5.0.1252.0, < 6.0.1638.0 >= 6.1, < 6.5.1638.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/M2Team/NanaZip/security/advisories/GHSA-89qw-8p49-32wf