Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

NanaZip — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in NanaZip, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories and vulnerability data for NanaZip, a compression utility, categorized primarily under weak cryptographic storage vulnerabilities and common software defects. The collection compiles known security flaws associated with this specific product, covering historical reports and recent disclosures across a defined time range. Readers can use this resource to track NanaZip's advisory history, analyze trends in weakness classes, and review the product's vulnerability record without needing to search multiple databases. The entries include descriptions of affected versions, impact assessments, and recommended mitigations, providing a consolidated view of the security posture for this application.

Vendor: M2Team

CVE ID Title CVSS Severity Published
CVE-2026-54616 NanaZip: Heap out-of-bounds read in NanaZip SquashFS LZ4 decompressor via unchecked negative return value CWE-125 7.1 High 2026-08-20
CVE-2026-55781 NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields CWE-400 - - 2026-07-10
CVE-2026-55780 NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size CWE-248 - - 2026-07-10
CVE-2026-55783 NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom archive handlers when extracting/testing the whole archive CWE-476 - - 2026-07-10
CVE-2026-55782 NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields CWE-400 - - 2026-07-10
CVE-2026-47223 NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflow CWE-125 5.4 Medium 2026-06-12
CVE-2026-47224 NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check CWE-125 4.3 Medium 2026-06-12
CVE-2026-47222 NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser via unsigned integer underflow CWE-125 5.4 Medium 2026-06-12
CVE-2026-44215 NanaZip: Heap out-of-bounds write in NanaZip UFS directory parser CWE-787 4.4 Medium 2026-05-12
CVE-2026-42445 NanaZip: Uncontrolled recursion in NanaZip UFS directory traversal causes stack exhaustion CWE-674 3.3 Low 2026-05-12
CVE-2026-42444 NanaZip: Unbounded resource consumption in NanaZip littlefs parser via attacker-controlled BlockCount CWE-770 3.3 Low 2026-05-12
CVE-2026-42443 NanaZip: Integer divide-by-zero in NanaZip UFS inode offset calculation CWE-369 3.3 Low 2026-05-12
CVE-2026-42442 NanaZip: Null-pointer dereference in NanaZip UFS parser when root inode is a symlink CWE-476 3.3 Low 2026-05-12
CVE-2026-42355 NanaZip: Uncontrolled recursion in NanaZip Electron ASAR parser causes stack exhaustion CWE-674 3.3 Low 2026-05-12
CVE-2026-42446 NanaZip: Stack out-of-bounds read in NanaZip ZealFS bitmap parser CWE-125 4.4 Medium 2026-05-12
CVE-2026-27711 NanaZip UFS Archive Parser Memory Corruption via Unvalidated Directory Record Length CWE-125 7.8AI High AI 2026-02-25
CVE-2026-27710 NanaZip .NET Single-File Parser Integer Underflow Leads to Unbounded Allocation (DoS) CWE-191 7.5AI High AI 2026-02-25
CVE-2026-27709 NanaZip .NET Single-File Manifest Parser Vulnerable to Out-of-Bounds Read via Unchecked RelativePathLength CWE-125 9.1AI Critical AI 2026-02-25
CVE-2026-27114 NanaZip has ROMFS Archive Infinite Loop CWE-835 7.5 - 2026-02-19
CVE-2026-27014 NanZip has ROMFS Archive Infinite Loop / Stack Overflow CWE-674 6.2 - 2026-02-19
CVE-2026-26282 NanaZip has DotNet Single file OOB Heap Read CWE-126 7.1 - 2026-02-19

All 21 known CVE vulnerabilities affecting NanaZip with full Chinese analysis, references, and POCs where available.