Junglewise Threat Intelligence

CVE-2026-42445: M2Team NanaZip uncontrolled recursion in UFS parser

CVE-2026-42445 · Severity: low · CVSS 3.3 · Published 2026-05-12

Technologies: M2Team NanaZip. Vendors: M2Team.

Executive brief

NanaZip is an open-source file archiver used to compress and decompress various file formats. A flaw in how it handles certain filesystem image files (UFS/UFS2) allows a specially crafted file to crash the application immediately upon opening. While this does not lead to data theft, it can disrupt operations and cause a denial of service for users attempting to process malicious archives.

Technical details

An uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser within NanaZip's 'GetAllPaths' function. The function lacks a recursion depth limit and does not track visited inodes, allowing a crafted UFS image with a deep directory tree or an inode cycle to exhaust the thread stack. On Windows, this results in a STATUS_STACK_OVERFLOW exception and a deterministic process crash. The vulnerability is triggered at archive open time due to file associations. It has been remediated in version 6.0.1698.0 by implementing proper recursion safeguards.

Affected products

  • M2Team NanaZip 5.0.1252.0 to before 6.0.1698.0

Timeline

  • 2025-02-01: other: Vulnerability introduced in version 5.0.1250.0
  • 2026-04-27: advisory: GitHub Security Advisory published
  • 2026-05-12: disclosed: CVE-2026-42445 published
  • 2026-05-12: patched: Fixed in version 6.0.1698.0

References

Related threats