PT-2026-57237 · Nanazip · Nanazip

CVE-2026-55782

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

2.4

Low

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NanaZip versions prior to 6.5.1749.0
Description The WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers using 32-bit section and custom-name length fields provided by the user without validating them against the actual file data. A specially crafted module can trigger multi-gigabyte allocations during the listing or extraction process via NameSize, Information.Size, and std::string or vector allocation paths, leading to memory exhaustion or process termination.
Recommendations Update to version 6.5.1749.0.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55782
GHSA-QXHC-2V6P-WM8M

Affected Products

Nanazip