CVE-2026-27114

Source
https://cve.org/CVERecord?id=CVE-2026-27114
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27114.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27114
Aliases
  • GHSA-hfg9-6rf9-5pgx
Published
2026-02-19T20:58:52.963Z
Modified
2026-02-27T00:35:50.656390Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
NanaZip has ROMFS Archive Infinite Loop
Details

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular NextOffset chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-835"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27114.json"
}
References

Affected packages

Git / github.com/m2team/nanazip

Affected ranges

Type
GIT
Repo
https://github.com/m2team/nanazip
Events

Affected versions

5.*
5.0.1252.0
5.0.1263.0
5.1.1252.0
5.1.1263.0
6.*
6.0.1461.0
6.0.1621.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27114.json"