PT-2026-26138 · Htslib · Htslib

Aviesrob

·

Published

2026-01-01

·

Updated

2026-03-18

·

CVE-2026-31964

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HTSlib versions 1.21.1 through 1.23.1
Description HTSlib is a library used for reading and writing bioinformatics file formats. A flaw exists in the CRAM decoder related to handling malformed sequence records. Specifically, the CONST, XPACK, and XRLE encodings do not correctly implement the necessary interface for handling records with omitted sequence or quality data. Attempting to decode these records results in a NULL pointer dereference, which typically causes the program to crash.
Recommendations HTSlib version 1.23.1 includes a fix for this issue. HTSlib version 1.22.2 includes a fix for this issue. HTSlib version 1.21.1 includes a fix for this issue.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-31964
GHSA-5W97-85GF-86RM

Affected Products

Htslib