PatchSiren cyber security CVE debrief
CVE-2026-103636 Apache Software Foundation CVE debrief
CVE-2026-103636 is an out-of-bounds read issue in Apache DataSketches C++'s VarOpt union deserialization. Affected versions are from 2.0.0-incubating to before 5.3.0. Only applications deserializing VarOpt unions from untrusted sources are impacted. The issue can cause a crash and potentially expose adjacent memory contents. Users should upgrade to version 5.3.0.
- Vendor
- Apache Software Foundation
- Product
- Apache DataSketches
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
Defenders of applications using Apache DataSketches C++ should assess exposure, especially if deserializing VarOpt unions from untrusted sources. This includes developers and security teams responsible for maintaining and securing applications that utilize Apache DataSketches C++.
Why it matters
CVE-2026-103636 is an out-of-bounds read issue in Apache DataSketches C++'s VarOpt union deserialization. Defenders should assess exposure in applications deserializing from untrusted sources, prioritize upgrading to version 5.3.0, and monitor for denial-of-service attempts. Evidence from official sources supports these defensive actions.
- Denial of service (crash) is possible when deserializing truncated VarOpt unions
- Potential exposure of adjacent memory contents when deserializing untrusted input
- Verification of affected versions and upgrade to 5.3.0 is necessary to mitigate the issue
- Assessment of application exposure based on input sources is required
Technical summary
The VarOpt union deserialization in Apache DataSketches C++ contains an out-of-bounds read vulnerability. When deserializing a truncated VarOpt union, the function reads up to 24 bytes past the end of the input. This can cause a crash (denial of service) and potentially expose adjacent memory contents. The issue affects Apache DataSketches C++ versions from 2.0.0-incubating to before 5.3.0. Affected applications are those that deserialize VarOpt unions from untrusted sources. Users should assess exposure and prioritize upgrading to version 5.3.0.
Defensive priority
Upgrade to version 5.3.0, assess exposure in applications deserializing VarOpt unions from untrusted sources, and monitor for potential denial-of-service attempts.
Recommended defensive actions
- Upgrade to Apache DataSketches C++ version 5.3.0
- Assess exposure in applications deserializing VarOpt unions from untrusted sources
- Monitor for potential denial-of-service attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the out-of-bounds read issue in Apache DataSketches C++. The issue is caused by improper deserialization of VarOpt unions, which can lead to a crash and potential exposure of adjacent memory contents.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103636 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103636
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103636 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103636
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/apache/datasketches-cpp/releases/tag/5.3.0
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/znn94s463w7wy125khcywxsp82y2qkq5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.