CVE-2026-31969General(htslib / htslib)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch htslib htslib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. When reading data encoded using the `BYTE_ARRAY_STOP` method, an out-by-one error in the `cram_byte_array_stop_decode_char()` function check for a full output buffer could result in a single attacker-controlled byte being written beyond the end of a heap allocation. Exploiting this bug causes a heap buffer overflow. If a user opens a file crafted to exploit this issue, it could lead to the program crashing, or overwriting of data and heap structures in ways not expected by the program. It may be possible to use this to obtain arbitrary code execution. Versions 1.23.1, 1.22.2 and 1.21.1 include fixes for this issue. There is no workaround for this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • htslib

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-19)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
htslib

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-19: 203-1803-19
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-181
General1
2026-03-192
Disclosure1Patch1
Full discourse3 posts
  • NerdieNews@NewsNerdie
    Patch

    Inductive Automation Ignition Software vulnerability could allow malicious code execution with elevated permissions. Users urged to update. CVE-2026-31969: HTSlib CRAM decoder heap buffer overflow may enable arbitrary code execution or system crashes. CVE-2026-32743: PX4 Autopilot affected by stack-based buffer overflow from improper MAVLink log request handling. CVE-2026-1276: IBM QRadar SIEM is vulnerable to cross-site scripting, risking arbitrary JavaScript injection by authenticated users. Stay sharp. Stay secure. #NerdieNews #CyberSecurity #InfoSec #BlueTeam #DFIR

    Post summary

    The post lists several CVEs and urges users to apply updates, highlighting specific technical details of the vulnerabilities but lacking evidence of active exploitation.

    0000029
    49 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31969 Heap Buffer Overflow in HTSlib CRAM Decoding via Out-of-Bounds Write https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31969

    Post summary

    The CVE-2026-31969 vulnerability—a heap buffer overflow in HTSlib's CRAM decoding—is disclosed with technical details, but no PoC, exploit, patch, or active exploitation is noted.

    0000041
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-31969 HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encod… https://www.cve.org/CVERecord?id=CVE-2026-31969

    Post summary

    The post merely references CVE-2026-31969 and links to its CVE record, providing no further technical, exploit, or mitigation details.

    0000062
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphtslibhtslib---
Apphtslibhtslib1.23--

Explore more