CVE-2026-27014
MEDIUMNanaZip 5.0.1252.0-6.0.1630.0 - DoS
Title source: llmDescription
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
Scores
CVSS v3
5.5
EPSS
0.0001
EPSS Percentile
2.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-674
Status
published
Affected Products (1)
m2team/nanazip
< 6.0.1630.0
Timeline
Published
Feb 19, 2026
Tracked Since
Feb 20, 2026