Vulnerability Details CVE-2026-27710
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Application` parser. A crafted bundle can force an integer underflow in header-size calculation and trigger an unbounded memory allocation attempt during archive open. Versions 6.0.1638.0 and 6.5.1638.0 fix the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.1%
CVSS Severity
CVSS v3 Score 5.0
Products affected by CVE-2026-27710
-
cpe:2.3:a:m2team:nanazip:5.0.1252.0
-
cpe:2.3:a:m2team:nanazip:5.0.1263.0
-
cpe:2.3:a:m2team:nanazip:5.1.1252.0
-
cpe:2.3:a:m2team:nanazip:5.1.1263.0
-
cpe:2.3:a:m2team:nanazip:6.0.1461.0
-
cpe:2.3:a:m2team:nanazip:6.0.1621.0
-
cpe:2.3:a:m2team:nanazip:6.0.1630.0
-
cpe:2.3:a:m2team:nanazip:6.0.1632.0