PT-2026-57237 · Nanazip · Nanazip
CVE-2026-55782
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v4.0
2.4
Low
| Vector | AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NanaZip versions prior to 6.5.1749.0
Description
The WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers using 32-bit section and custom-name length fields provided by the user without validating them against the actual file data. A specially crafted module can trigger multi-gigabyte allocations during the listing or extraction process via
NameSize, Information.Size, and std::string or vector allocation paths, leading to memory exhaustion or process termination.Recommendations
Update to version 6.5.1749.0.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nanazip