{"id":"CVE-2026-55782","summary":"NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields","details":"NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly archive handler in NanaZip.Codecs.Archive.WebAssembly.cpp allocates buffers from attacker-controlled 32-bit section and custom-name length fields without validating them against the data present in the file. A tiny crafted module can force multi-gigabyte allocations during listing or extraction through NameSize, Information.Size, and std::string or vector allocation paths, causing memory exhaustion or process termination. This issue is fixed in version 6.5.1749.0.","aliases":["GHSA-qxhc-2v6p-wm8m"],"modified":"2026-08-12T16:41:21.332510Z","published":"2026-07-10T16:46:38.842Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-400","CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55782.json"},"references":[{"type":"WEB","url":"https://github.com/M2Team/NanaZip/releases/tag/6.5.1749.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55782.json"},{"type":"ADVISORY","url":"https://github.com/M2Team/NanaZip/security/advisories/GHSA-qxhc-2v6p-wm8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55782"},{"type":"FIX","url":"https://github.com/M2Team/NanaZip/commit/1ce90f2d14a984476d0407a835273705607facf2"},{"type":"FIX","url":"https://github.com/M2Team/NanaZip/commit/56aee89037947410dd5e66f3a087e0f290484bae"},{"type":"FIX","url":"https://github.com/M2Team/NanaZip/commit/92b12a6e1eb0cf8e88fcc277aa7508ca1ff27db6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/m2team/nanazip","events":[{"introduced":"0"},{"fixed":"1ce90f2d14a984476d0407a835273705607facf2"},{"fixed":"56aee89037947410dd5e66f3a087e0f290484bae"},{"fixed":"92b12a6e1eb0cf8e88fcc277aa7508ca1ff27db6"},{"fixed":"1eaba2b09dfd3c78dab55e629ad4024d97d03567"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"6.5.1749.0"}]}}],"versions":["6.5.1742.0","6.5.1638.0","6.0.1632.0","6.0.1630.0","6.0.1621.0","6.0.1461.0","5.1.1263.0","5.0.1263.0","5.1.1252.0","5.0.1252.0","5.0.1250.0","5.0.1243.0","5.0.1215.0","5.0.1188.0","3.1.1080.0","3.5.1000.0","3.0.1000.0","3.5.996","3.0.996","3.0.756","2.1.451","2.0.450","2.0.396","2.0.376","2.0.313","1.2.253","1.2","1.2-Preview4","1.1+ServicingUpdate1-Preview3","1.1+ServicingUpdate1-Preview2","1.1+ServicingUpdate1-Preview1","1.1","1.1-Preview2-Update1","1.1-Preview2","1.1-Preview1","1.0","1.0-Preview4","1.0-Preview3","1.0-Preview2","1.0-Preview1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55782.json","vanir_signatures_modified":"2026-08-12T16:41:21Z","vanir_signatures":[{"id":"CVE-2026-55782-612b79a9","signature_type":"Line","signature_version":"v1","source":"https://github.com/m2team/nanazip/commit/56aee89037947410dd5e66f3a087e0f290484bae","target":{"file":"NanaZip.Codecs/NanaZip.Codecs.Archive.WebAssembly.cpp"},"deprecated":false,"digest":{"line_hashes":["192846759888911383859741309150996576967","266701842849406305084208735189006073237","340121456227470511554157713558246438822","255815476832353132545526818084132590566","72230822934347060279839640520500445430","119136196776460121848352152578145315010","116427903683559173252800947179820584100","294908209834283291070506350729945153719","289587315599161492527330618885564026296","20123223017741590463571029239013846574","295199347253306461764021780364788473416","9617303006230846534312638209332649011","10982232791494681259655124897382228750","311054053352331414085906877835939780305","57791665095195085617219570642334155767","333522260152813121733391263655994184138","163378525874246921743239564890505453879","269212974031789421428099975915486264603","175237493131711291472633283323163151065","33445783729109942383723512789340694163","156165917633842785453431893139871308168","152258499651537933706829059584068896032","228604177786423152750631582884480358186","24902853048044737428129183262901080498","202474866017284265941505877329760240005","250979059774671345138032528798654148026","130181662717215204812807417604855545044","285038014836939290716237267871333610944"],"threshold":0.9}},{"signature_version":"v1","source":"https://github.com/m2team/nanazip/commit/92b12a6e1eb0cf8e88fcc277aa7508ca1ff27db6","target":{"file":"NanaZip.Codecs/NanaZip.Codecs.Archive.WebAssembly.cpp"},"deprecated":false,"digest":{"line_hashes":["196170432935457569890490032121272913896","42831872171043228618295882771603735068","100517119506183486829063712872858080865","213211550476597944107846187334332740192"],"threshold":0.9},"id":"CVE-2026-55782-83e8cd6d","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}