SecAlerts
N

NanaZip

Security Risk Profile

31
/100
low

Security Risk Score

Comprehensive risk assessment based on 20 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 19, 2026 to present

20
Total CVEs
4
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
5.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
31/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
4
Medium
13
Low
3

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
Null Pointer Dereference
2
2
Integer Underflow
2
3
Integer Overflow
1
4
Divide by Zero
1

Most Affected Products

1. NanaZip NanaZip21
2. M2team Nanazip13

Recent Vulnerabilities

See more →
CVE-2026-54616
CVSS 7.1high

NanaZip: Heap out-of-bounds read in NanaZip SquashFS LZ4 decompressor via unchecked negative return value

Aug 20, 2026🔧 No Patch
CVE-2026-55781
CVSS 2.4low

NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields

Jul 10, 2026🔧 No Patch
CVE-2026-55783
CVSS 2.4low

NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom archive handlers when extracting/testing the whole archive

Jul 10, 2026🔧 No Patch
CVE-2026-55782
CVSS 2.4low

NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields

Jul 10, 2026🔧 No Patch
CVE-2026-47223
CVSS 5.4medium

NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflow

Jun 12, 2026🔧 No Patch
CVE-2026-47224
CVSS 4.3medium

NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check

Jun 12, 2026🔧 No Patch
CVE-2026-47222
CVSS 5.4medium

NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser via unsigned integer underflow

Jun 12, 2026🔧 No Patch
CVE-2026-44215
CVSS 7.1high

NanaZip: Heap out-of-bounds write in NanaZip UFS directory parser

May 12, 2026🔧 No Patch
CVE-2026-42445
CVSS 5.5medium

NanaZip: Uncontrolled recursion in NanaZip UFS directory traversal causes stack exhaustion

May 12, 2026🔧 No Patch
CVE-2026-42444
CVSS 5.5medium

NanaZip: Unbounded resource consumption in NanaZip littlefs parser via attacker-controlled BlockCount

May 12, 2026🔧 No Patch

Monitor NanaZip in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

NanaZip Security Vulnerabilities & Risk Score | 20 CVEs | SecAlerts - SecAlerts