🔐 CVE Alert

CVE-2026-27711

UNKNOWN 0.0

NanaZip UFS Archive Parser Memory Corruption via Unvalidated Directory Record Length

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser allows a crafted `.ufs/.ufs2/.img` file to trigger out-of-bounds memory access during archive open/listing. The bug is reachable via normal user file-open flow and can cause process crash, hang, and potentially exploitable heap corruption. Versions 6.0.1638.0 and 6.5.1638.0 fix the issue.

CWE CWE-125
Vendor m2team
Product nanazip
Published Feb 25, 2026
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for m2team nanazip

Be the first to know when new unknown vulnerabilities affecting m2team nanazip are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

M2Team / NanaZip
>= 5.0.1252.0, < 6.0.1638.0 >= 6.1, < 6.5.1638.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/M2Team/NanaZip/security/advisories/GHSA-rjwv-4w7x-hc9c