Samtools is a bioinformatics toolkit for parsing and manipulating sequence-alignment files, with a narrow but specialized footprint centered on the samtools command-line utility and the related HTSJDK Java library. Its vulnerability surface reflects the data-parsing and memory-management demands of genomic data processing, with observed weakness classes including resource-exposure issues, null-pointer dereferences, and use-after-free conditions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Samtools over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31972CRITICAL SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been aligned against a known referenc | Mar 18, 2026 | 9.8 | 30 | NO | NO |
CVE-2022-21126HIGH The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util/ | Nov 29, 2022 | 7.8 | 26 | NO | NO |
CVE-2026-31973HIGH SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in the cram-size command, used to write information about how wel | Mar 18, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Samtools.
Media articles that mention a CVE ID that affects a product developed by Samtools — matched by CVE ID, not by vendor name.