Out-of-bounds Vulnerability in Apache DataSketches C++ by Apache
CVE-2026-103513

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 October 2026

What is CVE-2026-103513?

An out-of-bounds read and write vulnerability exists in the deserialization process of the CPC sketch within Apache DataSketches C++. This issue arises when a crafted serialized CPC sketch is passed to the cpc_sketch::deserialize() function, either from a byte buffer or a stream. The vulnerability permits the decompressor to read beyond the available compressed data, as the read position validation occurs only after the decoding process. Additionally, in hybrid mode, it can enable writes outside of an internal heap buffer due to insufficient validation of decoded row indices. Key header fields and decoded values, including lg_k, lack proper validation, which could lead to heap memory corruption, causing application crashes and potential security breaches. Users are advised to upgrade to version 5.3.0, which addresses this vulnerability.

Affected Version(s)

Apache DataSketches 2.0.0-incubating <= 5.2.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

He Huang
NexusSan
.