CVE-2026-31964Disclosure(htslib / htslib)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. While most alignment records store DNA sequence and quality values, the format also allows them to omit this data in certain cases to save space. Due to some quirks of the CRAM format, it is necessary to handle these records carefully as they will actually store data that needs to be consumed and then discarded. Unfortunately the `CONST`, `XPACK` and `XRLE` encodings did not properly implement the interface needed to do this. Trying to decode records with omitted sequence or quality data using these encodings would result in an attempt to write to a NULL pointer. Exploiting this bug causes a NULL pointer dereference. Typically this will cause the program to crash. Versions 1.23.1, 1.22.2 and 1.21.1 include fixes for this issue. There is no workaround for this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • htslib

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
htslib

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-18: 3Technical Details · 2026-03-18: 203-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31964 - HTSlib CRAM decoder has a NULL Pointer Dereference Intel Report: https://ift.tt/jYc5sUX

    Post summary

    An alert announces that CVE-2026-31964 causes a null pointer dereference in HTSlib’s CRAM decoder, with a reference to an Intel report outlining the issue.

    0000031
    335 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31964 HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encod… https://www.cve.org/CVERecord?id=CVE-2026-31964

    Post summary

    The snippet refers to the CVE for HTSlib but provides no technical details, exploits, patches, or evidence of abuse, indicating a basic disclosure.

    0000064
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31964 NULL Pointer Dereference in HTSlib CRAM Decoder via Malformed Sequence Records https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31964

    Post summary

    The post announces CVE‑2026‑31964, describing a null‑pointer dereference in HTSlib’s CRAM decoder triggered by malformed sequence records, with no mention of PoC, exploitation, patches, or false‑positive status.

    0000034
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphtslibhtslib---
Apphtslibhtslib1.23--

Explore more