CVE-2026-27114

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:m2team:nanazip:*:*:*:*:*:*:*:*

History

26 Feb 2026, 00:16

Type Values Removed Values Added
Summary
  • (es) NanaZip es un archivador de ficheros, de código abierto. A partir de la versión 5.0.1252.0 y antes de la versión 6.0.1630.0, las cadenas circulares de 'NextOffset' provocan un bucle infinito en el analizador de archivos ROMFS. La versión 6.0.1630.0 soluciona el problema.
Summary (en) NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue. (en) NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.

20 Feb 2026, 19:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/M2Team/NanaZip/security/advisories/GHSA-hfg9-6rf9-5pgx - () https://github.com/M2Team/NanaZip/security/advisories/GHSA-hfg9-6rf9-5pgx - Exploit, Third Party Advisory
References () https://github.com/user-attachments/files/25274528/poc.zip - () https://github.com/user-attachments/files/25274528/poc.zip - Exploit
First Time M2team
M2team nanazip
CPE cpe:2.3:a:m2team:nanazip:*:*:*:*:*:*:*:*

19 Feb 2026, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 21:18

Updated : 2026-02-26 00:16


NVD link : CVE-2026-27114

Mitre link : CVE-2026-27114

CVE.ORG link : CVE-2026-27114


JSON object : View

Products Affected

m2team

  • nanazip
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')