CVE-2026-103501
Received Received - Intake

Heap Buffer Overflow in Apache DataSketches C++ HLL Sketch Deserialization

Vulnerability report for CVE-2026-103501, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Apache Software Foundation

Description

Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupon count was read from the input and used as the number of entries to copy into a fixed buffer of 8 entries, without checking it against the buffer's capacity. A crafted sketch could cause a write of up to 988 bytes past the end of this internal heap buffer. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 1.0.0-incubating before 5.3.0. Only applications that deserialize HLL sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Apache Software Foundation Apache DataSketches 1.0.0-incubating

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap buffer overflow vulnerability in Apache DataSketches C++ affecting HLL sketch deserialization. When processing sketches in LIST mode from untrusted sources, the system reads a coupon count from input and copies it into a fixed 8-entry buffer without checking size limits. A crafted sketch could write up to 988 extra bytes past the buffer, corrupting heap memory and potentially causing crashes or further exploits.

Impact Analysis

If your application deserializes HLL sketches from untrusted sources using affected versions (1.0.0-incubating to 5.2.0), this flaw could crash your program or allow attackers to execute arbitrary code. Systems processing untrusted sketch data are at risk; those handling only trusted sources remain unaffected.

Mitigation Strategies

Upgrade Apache DataSketches C++ to version 5.3.0 or later to fix the heap buffer overflow in HLL sketch deserialization. Only applications deserializing HLL sketches from untrusted sources are affected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103501. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart