M2team develops NanaZip, a compression utility that processes archive formats and sits in the path of file-handling workflows across user systems. The recurring vulnerability surface reflects the demands of parsing and decompressing untrusted archive data, with weakness classes including out-of-bounds reads, buffer over-reads, uncontrolled recursion, resource exhaustion, and divide-by-zero conditions that are endemic to format-parsing code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by M2team over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42446HIGH NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image parser in NanaZip. The vulnerab | May 12, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-44215HIGH NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. Th | May 12, 2026 | 7.1 | 26 | NO | NO |
CVE-2026-27114HIGH NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive par | Feb 19, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-42445MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-42444MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handl | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-42443MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-42442MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerabilit | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-42355MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-27711MEDIUM NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser al | Feb 26, 2026 | 6.6 | 22 | NO | NO |
CVE-2026-27709MEDIUM NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-o | Feb 26, 2026 | 6.6 | 22 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by M2team.
Media articles that mention a CVE ID that affects a product developed by M2team — matched by CVE ID, not by vendor name.