Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103513— Apache DataSketches: datasketches-cpp: Out-of-bounds read and write in the CPC sketch deserialization allows memory corruption via a crafted sketch

Quick assessment

Affected
Apache Software Foundation Apache DataSketches
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: Apache DataSketches C++ 仓库(datasketches-cpp)中 CPC sketch 反序列化过程存在越界读取和越界写入漏洞。 通过字节缓冲区或流传递给 的恶意构造的序列化 CPC sketch 数据,可导致解压缩器在压缩数据结束后仍继续读取,因为在解码完成之后才检查读取位置。在混合模式(hybrid flavor)下,由于未对解码后的行索引进行验证,还可能引发对内部堆缓冲区的越界写入。此外,若干其他头部字段和解码值(包括 )也未经过验证。这可能导致堆内

AI Predicted 8.1 Difficulty: Moderate

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Apache Software Foundation Apache DataSketches 2.0.0-incubating≤ 5.2.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103513

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache DataSketches: datasketches-cpp: Out-of-bounds read and write in the CPC sketch deserialization allows memory corruption via a crafted sketch
Source: CVE Program / CVE List V5
Vulnerability Description
Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). A crafted serialized CPC sketch passed to cpc_sketch::deserialize(), from either a byte buffer or a stream, can cause the decompressor to read past the end of the compressed data, because the read position was only checked after decoding finished. In the hybrid flavor, it can also cause a write outside an internal heap buffer, because decoded row indices were not validated. Several other header fields and decoded values, including lg_k, were also not validated. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deserialize CPC sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache DataSketches 2.0.0-incubating ~ 5.2.0 -

II. Public POCs for CVE-2026-103513

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103513

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-103513 (1)

Vendor Pages for CVE-2026-103513 (1)

Same Patch Batch · Apache Software Foundation · 2026-10-10 · 4 CVEs total

CVE-2026-103636 Apache DataSketches: datasketches-cpp: Out-of-bounds read in VarOpt union deserialization
CVE-2026-103635 Apache DataSketches: datasketches-cpp: Out-of-bounds read in compact Theta sketch deserial
CVE-2026-103501 Apache DataSketches: datasketches-cpp: HLL CouponList Deserialization Buffer Overflow allo

IV. Related Vulnerabilities

V. Comments for CVE-2026-103513

No comments yet


Leave a comment