CVE-2026-103635
Received Received - Intake

Out-of-bounds Read in Apache DataSketches C++ Theta Sketch

Vulnerability report for CVE-2026-103635, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: Apache Software Foundation

Description

Out-of-bounds read in the compact Theta sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() read header fields before checking that the input was long enough. For the compressed format, the size check could be defeated by a 32-bit overflow, and two header fields that control decoding were not validated; this also affected deserialization from a stream. A crafted or truncated sketch could cause a read past the end of the input. In the compressed case the over-read can be large, and the bytes read can become part of the deserialized sketch. This can cause a crash (denial of service) and could expose adjacent memory contents. This issue affects Apache DataSketches C++: from 3.1.0 before 5.3.0. Only applications that deserialize Theta sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Apache Software Foundation Apache DataSketches 3.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in Apache DataSketches C++ affecting Theta sketch deserialization. The functions compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() read header fields before checking input length. In compressed formats, a 32-bit overflow can bypass size checks, and unvalidated header fields allow crafted sketches to read past input buffers. This may cause crashes or expose adjacent memory.

Detection Guidance

To detect this vulnerability, check the version of Apache DataSketches C++ in use. If your version is between 3.1.0 and 5.2.0, the system is vulnerable. Run commands like 'find / -name "libdatasketches*" -exec ls -l {} \;' to locate the library and check its version.

Impact Analysis

The vulnerability can cause denial of service via application crashes. It may also expose sensitive memory contents adjacent to the input buffer. Only systems deserializing Theta sketches from untrusted sources are affected.

Mitigation Strategies

Upgrade Apache DataSketches C++ to version 5.3.0 or later immediately. If upgrading is not possible, restrict deserialization of Theta sketches to trusted sources only to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103635. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart