NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in the file. A tiny crafted module can force multi-gigabyte allocations during listing or extraction through NameSize, Information.Size, and std::string or vector allocation paths, causing memory exhaustion or process termination. This issue is fixed in version 6.5.1749.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-400",
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55782.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.5.1749.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55782.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"192846759888911383859741309150996576967",
"266701842849406305084208735189006073237",
"340121456227470511554157713558246438822",
"255815476832353132545526818084132590566",
"72230822934347060279839640520500445430",
"119136196776460121848352152578145315010",
"116427903683559173252800947179820584100",
"294908209834283291070506350729945153719",
"289587315599161492527330618885564026296",
"20123223017741590463571029239013846574",
"295199347253306461764021780364788473416",
"9617303006230846534312638209332649011",
"10982232791494681259655124897382228750",
"311054053352331414085906877835939780305",
"57791665095195085617219570642334155767",
"333522260152813121733391263655994184138",
"163378525874246921743239564890505453879",
"269212974031789421428099975915486264603",
"175237493131711291472633283323163151065",
"33445783729109942383723512789340694163",
"156165917633842785453431893139871308168",
"152258499651537933706829059584068896032",
"228604177786423152750631582884480358186",
"24902853048044737428129183262901080498",
"202474866017284265941505877329760240005",
"250979059774671345138032528798654148026",
"130181662717215204812807417604855545044",
"285038014836939290716237267871333610944"
],
"threshold": 0.9
},
"id": "CVE-2026-55782-612b79a9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/m2team/nanazip/commit/56aee89037947410dd5e66f3a087e0f290484bae",
"target": {
"file": "NanaZip.Codecs/NanaZip.Codecs.Archive.WebAssembly.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"196170432935457569890490032121272913896",
"42831872171043228618295882771603735068",
"100517119506183486829063712872858080865",
"213211550476597944107846187334332740192"
],
"threshold": 0.9
},
"id": "CVE-2026-55782-83e8cd6d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/m2team/nanazip/commit/92b12a6e1eb0cf8e88fcc277aa7508ca1ff27db6",
"target": {
"file": "NanaZip.Codecs/NanaZip.Codecs.Archive.WebAssembly.cpp"
}
}
]
"2026-08-12T16:41:21Z"