Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). (CVE-2026-103636)
Description
An out-of-bounds read vulnerability exists in the VarOpt union deserialization function of Apache DataSketches C++ versions from 2.0.0-incubating up to but not including 5.3.0. The flaw occurs when deserializing a truncated serialized union, causing reads beyond the input buffer and potentially exposing adjacent memory or causing a crash. This affects only applications that deserialize VarOpt unions from untrusted sources. Upgrading to version 5.3.0 resolves the issue.
Affected software
pkg:github/apache/datasketches-cppRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Apache DataSketches C++ arises from the var_opt_union::deserialize() function reading a 32-byte preamble after verifying only 8 bytes are available, leading to an out-of-bounds read of up to 24 bytes past the input end. Additionally, an unsigned subtraction used to compute the remaining size for the embedded sketch can wrap around, bypassing size checks and allowing further out-of-bounds reads. This can result in memory disclosure or a denial of service via crash. The issue affects versions from 2.0.0-incubating before 5.3.0 and only impacts applications deserializing VarOpt unions from untrusted inputs.
Potential Impact
Exploitation can cause application crashes (denial of service) and may expose adjacent memory contents, potentially leaking sensitive information. The impact is limited to scenarios where untrusted serialized VarOpt unions are deserialized.
Mitigation Recommendations
Users should upgrade to Apache DataSketches C++ version 5.3.0 or later, which contains the fix for this vulnerability. No other mitigations are indicated. Patch status is confirmed by the vendor recommendation to upgrade to 5.3.0.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9935-w26g-xf2m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-103636"]
- State
- PUBLISHED
Threat ID: 6acaad832cdf04f6565142c5
Added to database: 10/10/2026, 21:26:27 UTC
Last enriched: 10/10/2026, 21:30:11 UTC
Last updated: 10/11/2026, 04:48:07 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.