PT-2026-57235 · Nanazip · Nanazip

CVE-2026-55780

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

2.4

Low

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NanaZip versions prior to 6.5.1749.0
Description The .NET single-file bundle handler in NanaZip.Codecs.Archive.DotNetSingleFile.cpp determines the extraction buffer size based on the Size field of the bundle entry. This field is only checked for its sign and is not validated against the actual file size. A specially crafted bundle can trigger an attacker-controlled memory allocation within the Extract() function, leading to std::bad alloc or std::length error exceptions. These exceptions can cross the COM STDMETHODCALLTYPE boundary, resulting in a process crash.
Recommendations Update to version 6.5.1749.0.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55780
GHSA-PPM9-5267-RQ72

Affected Products

Nanazip