The Burrow Wheeler Aligner Project maintains a specialized bioinformatics tool widely used in genomic sequence alignment and analysis workflows, representing a focused but embedded component in research and diagnostic pipelines. Observed vulnerabilities in this product reflect the parsing and data-handling characteristics of sequence-processing software; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Burrow Wheeler Aligner Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10269CRITICAL BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file. | Mar 29, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-11371CRITICAL BWA (aka Burrow-Wheeler Aligner) 0.7.17 r1198 has a Buffer Overflow via a long prefix that is mishandled in bns_fasta2bntseq and bns_dump at btnseq.c. | Apr 20, 2019 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Burrow Wheeler Aligner Project.
Media articles that mention a CVE ID that affects a product developed by Burrow Wheeler Aligner Project — matched by CVE ID, not by vendor name.