CVE-2026-26282: NanaZip has DotNet Single file OOB Heap Read
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in .NET Single File bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26282?
CVE-2026-26282 is a high severity vulnerability due to its potential to cause crashes and disclose sensitive heap data.
How do I fix CVE-2026-26282?
To fix CVE-2026-26282, update NanaZip to version 6.0.1630.0 or later.
What harm can CVE-2026-26282 cause?
CVE-2026-26282 can lead to application crashes and potential exposure of sensitive information from heap memory.
Which versions of NanaZip are affected by CVE-2026-26282?
NanaZip versions starting from 5.0.1252.0 and prior to 6.0.1630.0 are affected by CVE-2026-26282.
Is there a workaround for CVE-2026-26282?
There are no known workarounds for CVE-2026-26282 other than updating to the fixed version.