CVE-2026-26282

Source
https://cve.org/CVERecord?id=CVE-2026-26282
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26282.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26282
Aliases
  • GHSA-ccpc-2222-xv5c
Published
2026-02-19T20:41:49.223Z
Modified
2026-07-15T01:49:18.022548427Z
Severity
  • 5.2 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
NanaZip has DotNet Single file OOB Heap Read
Details

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in .NET Single File bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.

Database specific
{
    "cwe_ids": [
        "CWE-126"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26282.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/m2team/nanazip

Affected ranges

Type
GIT
Repo
https://github.com/m2team/nanazip
Events
Database specific
{
    "cpe": "cpe:2.3:a:m2team:nanazip:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "5.0.1252.0"
        },
        {
            "fixed": "6.0.1630.0"
        }
    ]
}

Affected versions

5.*
5.0.1252.0
5.0.1263.0
5.1.1252.0
5.1.1263.0
6.*
6.0.1461.0
6.0.1621.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26282.json"