- Advisory: GHSA-q67r-9cfh-xc29 · CVE-2026-55783
- Severity: Low · CWE-476
- Status: publicly disclosed and fixed. Reported by Pig-Tail through coordinated disclosure.
NULL pointer dereference in Extract() of all seven NanaZip custom archive handlers when extracting/testing the whole archive
Write-up only. No standalone runnable PoC is published for this finding here — refer to the linked advisory for full technical detail, affected range, and the fixed version.