CVE-2017-1000206: Htslib

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution

Affected products

  • Htslib Htslib: up to and including 1.4.0

Published 2017-11-17. Last modified 2026-06-17.