CVE-2018-11130: Vcftools Project Vcftools

High severity, CVSS 7.8. EPSS: 22.1% chance of exploitation in the next 30 days.

The header::add_FORMAT_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted vcf file.

Affected products

Published 2018-05-17. Last modified 2026-06-17.