CVE-2026-27114

N

anaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.

Configurations

Configuration 1 (hide)

cpe:2.3:a:m2team:nanazip:*:*:*:*:*:*:*:*

History

26 Feb 2026, 00:16

Type Values Removed Values Added
Summary
  • (es) NanaZip es un archivador de ficheros, de código abierto. A partir de la versión 5.0.1252.0 y antes de la versión 6.0.1630.0, las cadenas circulares de 'NextOffset' provocan un bucle infinito en el analizador de archivos ROMFS. La versión 6.0.1630.0 soluciona el problema.
Summary (en) NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue. (en) NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.

20 Feb 2026, 19:21

Type Values Removed Values Added
References () https://github.com/M2Team/NanaZip/security/advisories/GHSA-hfg9-6rf9-5pgx - () https://github.com/M2Team/NanaZip/security/advisories/GHSA-hfg9-6rf9-5pgx - Exploit, Third Party Advisory
References () https://github.com/user-attachments/files/25274528/poc.zip - () https://github.com/user-attachments/files/25274528/poc.zip - Exploit
CPE cpe:2.3:a:m2team:nanazip:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time M2team nanazip
M2team

19 Feb 2026, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 21:18

Updated : 2026-02-26 00:16


NVD link : CVE-2026-27114

Mitre link : CVE-2026-27114

CVE.ORG link : CVE-2026-27114


JSON object : View

Products Affected
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')