PatchSiren cyber security CVE debrief
CVE-2026-103635 Apache Software Foundation CVE debrief
CVE-2026-103635 is an out-of-bounds read vulnerability in Apache DataSketches C++'s compact Theta sketch deserialization. The issue affects versions from 3.1.0 before 5.3.0 and can cause a denial of service and potential exposure of adjacent memory contents. Users are recommended to upgrade to version 5.3.0. This vulnerability is particularly concerning for applications that deserialize Theta sketches from untrusted sources, as it can lead to crashes and potential memory exposure. Affected users should assess their exposure and prioritize upgrading to version 5.3.0.
- Vendor
- Apache Software Foundation
- Product
- Apache DataSketches
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders and developers using Apache DataSketches C++ versions between 3.1.0 and 5.3.0 should assess exposure and prioritize upgrading to version 5.3.0. This is particularly important for applications that deserialize Theta sketches from untrusted sources.
Why it matters
CVE-2026-103635 is an out-of-bounds read vulnerability in Apache DataSketches C++'s compact Theta sketch deserialization. Defenders and developers using affected versions should prioritize upgrading to version 5.3.0, especially for applications deserializing Theta sketches from untrusted sources. The vulnerability can cause denial of service and potential memory exposure.
- Denial of service due to potential crashes
- Potential exposure of adjacent memory contents
- Need for verification of affected versions and remediation
- Upgrade priority to version 5.3.0 for vulnerable applications
Technical summary
The compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() functions in Apache DataSketches C++ read header fields before checking the input length, allowing for a potential out-of-bounds read. This issue affects versions from 3.1.0 before 5.3.0 and can cause a denial of service and potential exposure of adjacent memory contents. The vulnerability arises from the deserialization process, which does not properly validate the input length before accessing header fields. This can lead to a crash and potentially expose adjacent memory contents. Users are recommended to upgrade to version 5.3.0, which fixes this issue.
Defensive priority
Upgrade to version 5.3.0 to fix the out-of-bounds read vulnerability in Apache DataSketches C++'s compact Theta sketch deserialization.
Recommended defensive actions
- Upgrade to version 5.3.0
- Review and update affected applications that deserialize Theta sketches from untrusted sources
- Monitor for potential denial of service and memory exposure
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details on the out-of-bounds read vulnerability in Apache DataSketches C++'s compact Theta sketch deserialization. The issue affects versions from 3.1.0 before 5.3.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103635 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103635
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103635 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103635
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/apache/datasketches-cpp/releases/tag/5.3.0
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/15b86y9jstco39kzppjw7l5kvhjvwqvv
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.