CVE-2026-31965Disclosure(htslib / htslib)

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while reading CRAM records, validation of the reference id field occurred too late, allowing two out of bounds reads to occur before the invalid data was detected. The bug does allow two values to be leaked to the caller, however as the function reports an error it may be difficult to exploit them. It is also possible that the program will crash due to trying to access invalid memory. Versions 1.23.1, 1.22.2 and 1.21.1 include fixes for this issue. There is no workaround for this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • htslib

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
htslib

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-18: 3Technical Details · 2026-03-18: 203-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31965 - HTSlib CRAM reader has out-of-bounds reads due to improper validation of input Intel Report: https://ift.tt/RbLVsnT

    Post summary

    A new CVE-2026-31965 was disclosed, identifying an out‑of‑bounds read flaw in HTSlib's CRAM reader caused by improper input validation, with no exploit, patch, or PoC referenced.

    0000032
    335 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-31965 HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_sli… https://www.cve.org/CVERecord?id=CVE-2026-31965

    Post summary

    The passage merely references CVE‑2026‑31965 and mentions the affected library and file format without providing any exploitation, patch, or technical detail.

    0000068
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31965 Out-of-Bounds Read Vulnerability in HTSlib CRAM Decoding Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31965

    Post summary

    The post announces CVE-2026-31965 as an out‑of‑bounds read flaw in HTSlib’s CRAM decoder, linking to a detail page yet offering no PoC, exploit, or patch information.

    0000036
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphtslibhtslib---
Apphtslibhtslib1.23--

Explore more