
CVE-2026-31970: HTSlib <= 1.23 heap buffer overflow in the BGZF index file reader https://www.openwall.com/lists/oss-security/2026/03/18/9 9 CVEs in HTSlib <= 1.23 in the CRAM file reader https://www.openwall.com/lists/oss-security/2026/03/18/10 HTSlib is a library for reading and writing bioinformatics file formats. See also next tweet.
Post summary
HTSlib versions <=1.23 contain a heap buffer overflow in the BGZF index file reader, identified as CVE-2026-31970, with 9 additional CVEs affecting the CRAM file reader. The disclosure provides technical details but no evidence of exploitation, PoC, or fixes.

