CVE-2026-31962Patch(htslib / htslib)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch htslib htslib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DNA sequence and quality values, the format also allows them to omit this data in certain cases to save space. Due to some quirks of the CRAM format, it is necessary to handle these records carefully as they will actually store data that needs to be consumed and then discarded. Unfortunately the `cram_decode_seq()` did not handle this correctly in some cases. Where this happened it could result in reading a single byte from beyond the end of a heap allocation, followed by writing a single attacker-controlled byte to the same location. Exploiting this bug causes a heap buffer overflow. If a user opens a file crafted to exploit this issue, it could lead to the program crashing, or overwriting of data and heap structures in ways not expected by the program. It may be possible to use this to obtain arbitrary code execution. Versions 1.23.1, 1.22.2 and 1.21.1 include fixes for this issue. There is no workaround for this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-125CWE-129CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • htslib

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-28)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
htslib

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-28: 2Patch / Workaround · 2026-03-28: 2Technical Details · 2026-03-19: 1Technical Details · 2026-03-28: 203-1803-1903-28
Signal classification3 categories
Patch
250.0%
General
125.0%
Disclosure
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-181
General1
2026-03-191
Disclosure1
2026-03-282
Patch2
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #Fedora 42 just pushed a critical update for Samtools to fix CVE-2026-31962 (heap buffer overflow). 🧬🔒 Read more: 👉 https://tinyurl.com/2udnjzha #Security https://t.co/Y3UPNs7Wso

    Post summary

    Fedora 42 released a critical update for Samtools, fixing CVE‑2026‑31962, a heap buffer overflow vulnerability.

    0000041
    1.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical htslib flaw CVE-2026-31962 in Fedora 42 enables code execution via crafted CRAM files, impacting samtools and bcftools users until updated to 1.23.1. https://threatcluster.io/cluster/critical-heap-overflow-vulnerability-in-fedora-42-affects-sa-e2f9078e

    Post summary

    The post announces a serious CVE-2026-31962 in Fedora 42 that allows code execution through crafted CRAM files, advising users to update to version 1.23.1 to address the issue.

    0000046
    128 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31962 Heap Buffer Overflow in HTSlib CRAM Decoding Affecting Multiple V... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31962 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The text announces a new vulnerability (CVE-2026-31962) identified as a heap buffer overflow in HTSlib CRAM decoding and directs readers to a details page, but it does not provide PoC, exploit code, or mitigation information.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-31962 HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment re… https://www.cve.org/CVERecord?id=CVE-2026-31962

    Post summary

    The excerpt merely references CVE‑2026‑31962 and provides context about HTSlib, without indicating exploits, patches, or technical details.

    0000067
    56.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphtslibhtslib---
Apphtslibhtslib1.23--

Explore more