← Vulnerability feed

Vulnerability record · CVE-2026-42355 · published 12 May 2026

CVE-2026-42355: M2team nanazip vulnerability

M2team · Nanazip

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and the handler's GetAllPaths function recurse without depth limits, exhausting the thread stack and crashing the NanaZip process. This vulnerability is fixed in 6.0.1698.0.

5.5 CVSS 3.1 Medium EPSS 0.15% · top 96.6% CWE-674 · CWE-674
5.5CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and the handler's GetAllPaths function recurse without depth limits, exhausting the thread stack and crashing the NanaZip process. This vulnerability is fixed in 6.0.1698.0.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-42355 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.1CVE-2026-44215M2team nanazip out-of-bounds write vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesys…EPSS 0.26%7.1CVE-2026-42446M2team nanazip out-of-bounds read vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image …EPSS 0.16%5.5CVE-2026-42442M2team nanazip null pointer dereference vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image pars…EPSS 0.15%5.5CVE-2026-42443M2team nanazip divide by zero vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parse…EPSS 0.15%5.5CVE-2026-42444M2team nanazip allocation without limits vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem ima…EPSS 0.15%5.5CVE-2026-42445M2team nanazip vulnerabilityNanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesyst…EPSS 0.15%5.2CVE-2026-26282M2team nanazip out-of-bounds read vulnerabilityNanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NE…EPSS 0.16%5.1CVE-2026-27709M2team nanazip out-of-bounds read vulnerabilityNanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File A…EPSS 0.16%

Source: NIST National Vulnerability Database (record CVE-2026-42355), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.