CVE-2026-27014

MEDIUM

NanaZip 5.0.1252.0-6.0.1630.0 - DoS

Title source: llm

Description

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-674
Status published

Affected Products (1)

m2team/nanazip < 6.0.1630.0

Timeline

Published Feb 19, 2026
Tracked Since Feb 20, 2026