CVE Explorer
CVE-2026-31970
HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZIP [BGZF] files. In the GZI loading function, `bgzf_index_load_hfile()`, it was possible to trigger an integer overflow, leading to an under- or zero-sized buffer being allocated to store the index. Sixteen zero bytes would then be written to this buffer, and, depending on the result of the overflow the rest of the file may also be loaded into the buffer as well. If the func
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 5 assertions
{"cweId":"CWE-190","description":"CWE-190: Integer Overflow or Wraparound","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-1284","description":"CWE-1284: Improper Validation of Specified Quantity in Input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/4/descriptions/0
{"cweId":"CWE-122","description":"CWE-122: Heap-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-131","description":"CWE-131: Incorrect Calculation of Buffer Size","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-787","description":"CWE-787: Out-of-bounds Write","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/3/descriptions/0
Affected products and versions
1 source assertion{"product":"htslib","vendor":"samtools","versions":[{"status":"affected","version":"< 1.21.1"},{"status":"affected","version":">= 1.22, < 1.22.2"},{"status":"affected","version":"= 1.23"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
5 source assertions{"cweId":"CWE-190","description":"CWE-190: Integer Overflow or Wraparound","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-1284","description":"CWE-1284: Improper Validation of Specified Quantity in Input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/4/descriptions/0
{"cweId":"CWE-122","description":"CWE-122: Heap-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-131","description":"CWE-131: Incorrect Calculation of Buffer Size","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-787","description":"CWE-787: Out-of-bounds Write","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/problemTypes/3/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/03/18/9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/adp/1/references/0
{"name":"https://github.com/samtools/htslib/commit/6dd0d7d0e9e7e2e173a28969e624db8bc8bb5828","tags":["x_refsource_MISC"],"url":"https://github.com/samtools/htslib/commit/6dd0d7d0e9e7e2e173a28969e624db8bc8bb5828"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/references/1
{"name":"https://github.com/samtools/htslib/security/advisories/GHSA-p345-84hx-fq6q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/samtools/htslib/security/advisories/GHSA-p345-84hx-fq6q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:130fa9492e0a0439203e21c179910f02aff47a41efc7aedf08ec146cef419c91 · sha256:12050e8ddf1a2d0b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.