Infinite Loop Vulnerability in NanaZip File Archive Software
CVE-2026-27114

5.1MEDIUM

Key Information:

Vendor

M2team

Status
Vendor
CVE Published:
19 February 2026

What is CVE-2026-27114?

NanaZip, an open source file archiving tool, is affected by a vulnerability that causes an infinite loop in its ROMFS archive parser. Versions 5.0.1252.0 and earlier are susceptible due to circular NextOffset chains within the parsing process, which can lead to excessive resource consumption. Users are encouraged to update to version 6.0.1630.0, where this issue has been resolved to ensure optimal performance and security.

Affected Version(s)

NanaZip >= 5.0.1252.0, < 6.0.1630.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.