← Vulnerability feed

Vulnerability record · CVE-2026-26282 · published 19 February 2026

CVE-2026-26282: M2team nanazip out-of-bounds read vulnerability

M2team · Nanazip

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.

5.2 CVSS 4.0 Medium EPSS 0.16% · top 95.1% CWE-126 · CWE-126CWE-125 · Out-of-bounds read
5.2CVSS 4.0 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-26282 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.1CVE-2026-44215M2team nanazip out-of-bounds write vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesys…EPSS 0.26%7.1CVE-2026-42446M2team nanazip out-of-bounds read vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image …EPSS 0.16%5.5CVE-2026-42355M2team nanazip vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive …EPSS 0.15%5.5CVE-2026-42442M2team nanazip null pointer dereference vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image pars…EPSS 0.15%5.5CVE-2026-42443M2team nanazip divide by zero vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parse…EPSS 0.15%5.5CVE-2026-42444M2team nanazip allocation without limits vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem ima…EPSS 0.15%5.5CVE-2026-42445M2team nanazip vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesyst…EPSS 0.15%5.1CVE-2026-27709M2team nanazip out-of-bounds read vulnerabilityNanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File A…EPSS 0.16%

Source: NIST National Vulnerability Database (record CVE-2026-26282), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.