Out-of-Bounds Read in Apache DataSketches C++ Affects Multiple Versions
CVE-2026-103635

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 October 2026

What is CVE-2026-103635?

An out-of-bounds read vulnerability has been identified in the deserialization process of the compact Theta sketch within Apache DataSketches C++. The methods compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() do not properly verify the length of the input before reading header fields. This oversight can potentially allow an attacker to create a crafted or truncated sketch that leads to reading beyond the allocated input, causing a denial of service due to crashes and possible exposure of sensitive adjacent memory contents. Only applications deserializing Theta sketches from untrusted sources are at risk. Apache recommends updating to version 5.3.0 to mitigate this issue.

Affected Version(s)

Apache DataSketches 3.1.0 <= 5.2.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

He Huang
NexusSan
.