CVE-2026-31965 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: March 19, 2026
HTSlib - Out of Bounds Read
Published: March 18, 2026Updated: March 19, 2026Remote Exploitable
Overview
HTSlib contains an out of bounds read caused by late validation of the reference id field in the cram_decode_slice() function, letting attackers leak memory values or cause crashes, exploit requires crafted CRAM data.
Severity & Score
Severity: High
CVSS Score: 8.2
Impact
Attackers can leak memory values or cause program crashes, potentially leading to denial of service or information disclosure.
Mitigation
Update to versions 1.23.1, 1.22.2, 1.21.1 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-31965
- Severity
- High
- CVSS Score
- 8.2
- Type
- out_of_bounds_rw
- Status
- confirmed
CWE
- CWE-125
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H