CVE-2026-31970General(htslib / htslib)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_load_hfile()`, it was possible to trigger an integer overflow, leading to an under- or zero-sized buffer being allocated to store the index. Sixteen zero bytes would then be written to this buffer, and, depending on the result of the overflow the rest of the file may also be loaded into the buffer as well. If the function did attempt to load the data, it would eventually fail due to not reading the expected number of records, and then try to free the overflowed heap buffer. Exploiting this bug causes a heap buffer overflow. If a user opens a file crafted to exploit this issue, it could lead to the program crashing, or overwriting of data and heap structures in ways not expected by the program. It may be possible to use this to obtain arbitrary code execution. Versions 1.23.1, 1.22.2 and 1.21.1 include fixes for this issue. The easiest work-around is to discard any `.gzi` index files from untrusted sources, and use the `bgzip -r` option to recreate them.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-131CWE-190CWE-787CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • htslib

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
htslib

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Technical Details · 2026-03-19: 103-1803-19
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-181
General1
2026-03-191
Disclosure1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-31970: HTSlib <= 1.23 heap buffer overflow in the BGZF index file reader https://www.openwall.com/lists/oss-security/2026/03/18/9 9 CVEs in HTSlib <= 1.23 in the CRAM file reader https://www.openwall.com/lists/oss-security/2026/03/18/10 HTSlib is a library for reading and writing bioinformatics file formats. See also next tweet.

    Post summary

    HTSlib versions <=1.23 contain a heap buffer overflow in the BGZF index file reader, identified as CVE-2026-31970, with 9 additional CVEs affecting the CRAM file reader. The disclosure provides technical details but no evidence of exploitation, PoC, or fixes.

    10031379
    4.4K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-31970 HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function,… https://www.cve.org/CVERecord?id=CVE-2026-31970

    Post summary

    The snippet references CVE-2026-31970 and a brief note on HTSlib’s GZI loading function, providing no actionable details about exploitation, patches, or technical specifics.

    0000067
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphtslibhtslib---
Apphtslibhtslib1.23--

Explore more