CVE-2026-27014

MEDIUM

NanaZip 5.0.1252.0-6.0.1630.0 - DoS

Title source: llm
STIX 2.1

Description

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 4.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-674
Status published
Products (1)
m2team/nanazip 5.0.1252.0 - 6.0.1630.0
Published Feb 19, 2026
Tracked Since Feb 20, 2026