CVE-2026-31971: Htslib Cram Byte Array Len Overruncve-2026-31971-htslib-cram-byte-array-len-overrun
A codec decodes an item length but fails to validate it against the allocated output buffer size before decoding the items into memory. This can lead to a heap or stack buffer overflow when an attacker supplies a byte array length larger than the buffer bounds.