CVE-2026-31969 | samtools htslib up to 1.21.0/1.22.1/1.23 cram_byte_array_stop_decode_char heap-based overflow (GHSA-q4cj-f4h5-fqgc / EUVD-2026-12944)
A vulnerability classified as critical has been found in samtools htslib up to 1.21.0/1.22.1/1.23. This affects the function cram_byte_array_stop_decode_char. The manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2026-31969. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.