6.9

CVSS4.0

CVE-2026-31964 - HTSlib CRAM decoder has a NULL Pointer Dereference

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. While most alignment records store DNA sequence and quality values, the format also allows them to omi…

📅 Published: March 18, 2026, 6:27 p.m. 🔄 Last Modified: March 18, 2026, 6:27 p.m.

8.8

CVSS4.0

CVE-2026-31963 - HTSlib CRAM reader has heap buffer overflow due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses reference-based compression so that instead of storing the full sequence for each alignment record it st…

📅 Published: March 18, 2026, 6:22 p.m. 🔄 Last Modified: March 18, 2026, 6:22 p.m.

2.1

CVSS4.0

CVE-2026-3479 - pkgutil.get_data() does not enforce documented restrictions

pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

📅 Published: March 18, 2026, 6:13 p.m. 🔄 Last Modified: March 18, 2026, 6:13 p.m.

8.8

CVSS4.0

CVE-2026-31962 - HTSlib CRAM reader has heap buffer overflow due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DNA sequence and quality values, the format also allows them to omit this data in certain cases to save space. Due to som…

📅 Published: March 18, 2026, 6:08 p.m. 🔄 Last Modified: March 18, 2026, 6:08 p.m.

7.5

CVSS3.1

CVE-2026-27135 - nghttp2 Denial of service: Assertion failure due to the missing state validation

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They mig…

📅 Published: March 18, 2026, 5:59 p.m. 🔄 Last Modified: March 18, 2026, 5:59 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here