LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-31972

CVE-2026-31972 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 19, 2026

SAMtools - Use After Free

Published: March 18, 2026Updated: March 19, 2026Remote Exploitable

Overview

SAMtools < 1.21.1 and < 1.22 contain a use-after-free vulnerability in the mpileup command caused by premature discarding of reference data, letting attackers cause information disclosure or program crash, exploit requires crafted input data.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 1.5%(Probability of exploitation in next 30 days)

Impact

Attackers can cause program crashes or leak information about program state, potentially disrupting bioinformatics workflows.

Mitigation

Update to version 1.21.1 or 1.22 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 19, 2026

šŸ”“ CVE-2026-31972 - Critical (9.8) SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been aligned against a known reference. On each output line it writes the reference position, optionally... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-31972/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-31972
Severity
Critical
CVSS Score
9.8
Type
use_after_free
Status
confirmed
EPSS
1.5%
Social Posts
1

CWE

  • CWE-416

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

1.5%Probability of exploitation in the next 30 days