Nanazip
Vendor:
First CVE: Feb 19, 2026 · Active for under a year
13
Total CVEs
More Total CVEs than 92% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nanazip over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2026
5 months ago
Most Recent CVE
May 12, 2026
76 days ago
CVE Severity & Scoring
Nanazip13 CVEs
77%
23%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local10 (76.9%)
Network3 (23.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (7.7%)
Unknown0 (0.0%)
Required12 (92.3%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None9 (69.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42446HIGH NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in the ZealFS filesystem image parser in NanaZip. The vulnerab | May 12, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-44215HIGH NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write exists in the UFS/UFS2 filesystem image parser in NanaZip. Th | May 12, 2026 | 7.1 | 26 | NO | NO |
CVE-2026-27114HIGH NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive par | Feb 19, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-42445MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-42444MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem image parser in NanaZip. The handl | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-42443MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerability | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-42442MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the UFS/UFS2 filesystem image parser in NanaZip. The vulnerabilit | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-42355MEDIUM NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When | May 12, 2026 | 5.5 | 23 | NO | NO |
CVE-2026-27711MEDIUM NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser al | Feb 26, 2026 | 6.6 | 22 | NO | NO |
CVE-2026-27709MEDIUM NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-o | Feb 26, 2026 | 6.6 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Nanazip
Top CWEs
Versions
No cataloged versions.