PT-2026-26136 · Htslib · Htslib

·

CVE-2026-31962

·

Published

2026-01-01

·

Updated

2026-08-30

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions HTSlib versions prior to 1.23.1
Description HTSlib is a library used for reading and writing bioinformatics file formats. A heap buffer overflow exists in the cram decode seq() function when decoding CRAM files. This occurs because the function incorrectly handles records that omit DNA sequence and quality values, leading to a read and write operation beyond the bounds of a heap allocation. Exploitation of this issue, through a crafted CRAM file, could lead to program crashes, data corruption, or potentially arbitrary code execution.
Recommendations Update to HTSlib version 1.23.1 or later.

Exploit

Fix

Out of bounds Read

Improper Validation of Array Index

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31962
GHSA-XXMP-V7H3-GPWP
OESA-2026-2547
OESA-2026-2757
OESA-2026-3491

Affected Products

Htslib