PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103635 Apache Software Foundation CVE debrief

CVE-2026-103635 is an out-of-bounds read vulnerability in Apache DataSketches C++'s compact Theta sketch deserialization. The issue affects versions from 3.1.0 before 5.3.0 and can cause a denial of service and potential exposure of adjacent memory contents. Users are recommended to upgrade to version 5.3.0. This vulnerability is particularly concerning for applications that deserialize Theta sketches from untrusted sources, as it can lead to crashes and potential memory exposure. Affected users should assess their exposure and prioritize upgrading to version 5.3.0.

Vendor
Apache Software Foundation
Product
Apache DataSketches
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders and developers using Apache DataSketches C++ versions between 3.1.0 and 5.3.0 should assess exposure and prioritize upgrading to version 5.3.0. This is particularly important for applications that deserialize Theta sketches from untrusted sources.

Why it matters

CVE-2026-103635 is an out-of-bounds read vulnerability in Apache DataSketches C++'s compact Theta sketch deserialization. Defenders and developers using affected versions should prioritize upgrading to version 5.3.0, especially for applications deserializing Theta sketches from untrusted sources. The vulnerability can cause denial of service and potential memory exposure.

  • Denial of service due to potential crashes
  • Potential exposure of adjacent memory contents
  • Need for verification of affected versions and remediation
  • Upgrade priority to version 5.3.0 for vulnerable applications

Technical summary

The compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() functions in Apache DataSketches C++ read header fields before checking the input length, allowing for a potential out-of-bounds read. This issue affects versions from 3.1.0 before 5.3.0 and can cause a denial of service and potential exposure of adjacent memory contents. The vulnerability arises from the deserialization process, which does not properly validate the input length before accessing header fields. This can lead to a crash and potentially expose adjacent memory contents. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

Defensive priority

Upgrade to version 5.3.0 to fix the out-of-bounds read vulnerability in Apache DataSketches C++'s compact Theta sketch deserialization.

Recommended defensive actions

  • Upgrade to version 5.3.0
  • Review and update affected applications that deserialize Theta sketches from untrusted sources
  • Monitor for potential denial of service and memory exposure
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the out-of-bounds read vulnerability in Apache DataSketches C++'s compact Theta sketch deserialization. The issue affects versions from 3.1.0 before 5.3.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103635 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103635

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103635 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103635

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.