CVE-2026-103513
Received Received - Intake

Out-of-bounds Read and Write in Apache DataSketches C++ CPC Sketch Deserialization

Vulnerability report for CVE-2026-103513, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Apache Software Foundation

Description

Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). A crafted serialized CPC sketch passed to cpc_sketch::deserialize(), from either a byte buffer or a stream, can cause the decompressor to read past the end of the compressed data, because the read position was only checked after decoding finished. In the hybrid flavor, it can also cause a write outside an internal heap buffer, because decoded row indices were not validated. Several other header fields and decoded values, including lg_k, were also not validated. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deserialize CPC sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Apache Software Foundation Apache DataSketches 2.0.0-incubating

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read and write issue in Apache DataSketches C++ affecting versions 2.0.0-incubating through 5.2.0. When a crafted serialized CPC sketch is passed to the deserialize function, it can cause the decompressor to read past the end of compressed data because position checks happen after decoding. In the hybrid flavor, it may also write outside an internal heap buffer due to unvalidated row indices. Other header fields and values like lg_k are also unvalidated, risking heap corruption, crashes, or further exploitation.

Detection Guidance

Detecting this vulnerability requires checking the version of Apache DataSketches C++ in use. Run commands like 'find / -name "libdatasketches*" 2>/dev/null' to locate the library, then check its version with 'strings [library_path] | grep -i version' or 'ldd [executable] | grep datasketches'. If the version is between 2.0.0-incubating and 5.2.0, the system is vulnerable.

Impact Analysis

If you use Apache DataSketches C++ to deserialize CPC sketches from untrusted sources, this flaw could corrupt heap memory, leading to crashes or potential code execution. Systems processing untrusted serialized sketches are most at risk, as attackers could craft malicious inputs to trigger these memory issues.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It is a memory corruption issue in Apache DataSketches C++ that could lead to crashes or potential exploitation if untrusted serialized sketches are processed. Compliance impacts would depend on how the affected library is used in a system handling regulated data.

Mitigation Strategies

Immediately upgrade Apache DataSketches C++ to version 5.3.0 or later. If upgrading is not possible, disable deserialization of CPC sketches from untrusted sources or implement strict input validation for serialized sketches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103513. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart