A vulnerability labeled as problematic has been found in samtools htslib up to 1.21.0/1.22.1/1.23. This affects the function cram_decode_slice. The manipulation results in out-of-bounds read.

This vulnerability is identified as CVE-2026-31965. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.