HTSlib is a widely embedded C library for reading and writing genomic data formats (SAM, BAM, CRAM, VCF), ubiquitous in bioinformatics pipelines and research tooling despite its narrow product scope. Vulnerabilities affecting the library skew toward serious outcomes, with a notable share reaching critical severity, and recur through memory-safety and input-validation weakness classes—out-of-bounds writes, heap-based buffer overflows, and improper array-index validation—that reflect the parsing complexity inherent to binary genomic file handling. Defenders should prioritize inventory of downstream bioinformatics platforms and research infrastructure that embed this library, as remediation often depends on those tools rebuilding and updating; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Htslib over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31962HIGH HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DN | Mar 18, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-31969HIGH HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compr | Mar 18, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-31967CRITICAL HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function | Mar 18, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-31966CRITICAL HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant d | Mar 18, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-31965HIGH HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function | Mar 18, 2026 | 8.2 | 27 | NO | NO |
CVE-2026-31963HIGH HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant d | Mar 18, 2026 | 8.1 | 27 | NO | NO |
CVE-2018-13845CRITICAL An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c. | Jul 10, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-1000206CRITICAL samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution | Nov 17, 2017 | 9.8 | 27 | NO | NO |
CVE-2026-31970HIGH HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_l | Mar 18, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-31971HIGH HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compr | Mar 18, 2026 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Htslib.
Media articles that mention a CVE ID that affects a product developed by Htslib — matched by CVE ID, not by vendor name.