Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Htslib

First CVE: Nov 17, 2017Active for: 9 yearsTotal CVEs: 16
46.9
VTI Score
High

HTSlib is a widely embedded C library for reading and writing genomic data formats (SAM, BAM, CRAM, VCF), ubiquitous in bioinformatics pipelines and research tooling despite its narrow product scope. Vulnerabilities affecting the library skew toward serious outcomes, with a notable share reaching critical severity, and recur through memory-safety and input-validation weakness classes—out-of-bounds writes, heap-based buffer overflows, and improper array-index validation—that reflect the parsing complexity inherent to binary genomic file handling. Defenders should prioritize inventory of downstream bioinformatics platforms and research infrastructure that embed this library, as remediation often depends on those tools rebuilding and updating; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Htslib over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2017
8 years ago
Most Recent CVE
Mar 18, 2026
128 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-31962HIGH
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DN
Mar 18, 20268.829NONO
CVE-2026-31969HIGH
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compr
Mar 18, 20268.127NONO
CVE-2026-31967CRITICAL
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function
Mar 18, 20269.127NONO
CVE-2026-31966CRITICAL
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant d
Mar 18, 20269.127NONO
CVE-2026-31965HIGH
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function
Mar 18, 20268.227NONO
CVE-2026-31963HIGH
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant d
Mar 18, 20268.127NONO
CVE-2018-13845CRITICAL
An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c.
Jul 10, 20189.827NONO
CVE-2017-1000206CRITICAL
samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution
Nov 17, 20179.827NONO
CVE-2026-31970HIGH
HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_l
Mar 18, 20268.126NONO
CVE-2026-31971HIGH
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compr
Mar 18, 20268.125NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
69%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None9 (56.3%)
Unknown0 (0.0%)
Required7 (43.8%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None15 (93.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Htslib.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Htslib — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Htslib's Products

View all 2 CNAs →

Top CWEs