Skip to main content

Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). (CVE-2026-103636)

0
High
Published: 10/10/2026 (10/10/2026, 12:30:25 UTC)
Source: GCVE Database

Description

An out-of-bounds read vulnerability exists in the VarOpt union deserialization function of Apache DataSketches C++ versions from 2.0.0-incubating up to but not including 5.3.0. The flaw occurs when deserializing a truncated serialized union, causing reads beyond the input buffer and potentially exposing adjacent memory or causing a crash. This affects only applications that deserialize VarOpt unions from untrusted sources. Upgrading to version 5.3.0 resolves the issue.

Affected software

GitHub Actionsmore threats →ai
apache/datasketches-cpp
pkg:github/apache/datasketches-cpp
Affected versions
>=2.0.0-incubating <5.3.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/10/2026, 21:30:11 UTC

Technical Analysis

The vulnerability in Apache DataSketches C++ arises from the var_opt_union::deserialize() function reading a 32-byte preamble after verifying only 8 bytes are available, leading to an out-of-bounds read of up to 24 bytes past the input end. Additionally, an unsigned subtraction used to compute the remaining size for the embedded sketch can wrap around, bypassing size checks and allowing further out-of-bounds reads. This can result in memory disclosure or a denial of service via crash. The issue affects versions from 2.0.0-incubating before 5.3.0 and only impacts applications deserializing VarOpt unions from untrusted inputs.

Potential Impact

Exploitation can cause application crashes (denial of service) and may expose adjacent memory contents, potentially leaking sensitive information. The impact is limited to scenarios where untrusted serialized VarOpt unions are deserialized.

Mitigation Recommendations

Users should upgrade to Apache DataSketches C++ version 5.3.0 or later, which contains the fix for this vulnerability. No other mitigations are indicated. Patch status is confirmed by the vendor recommendation to upgrade to 5.3.0.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-9935-w26g-xf2m
Osv Schema Version
1.4.0
Aliases
["CVE-2026-103636"]
State
PUBLISHED

Threat ID: 6acaad832cdf04f6565142c5

Added to database: 10/10/2026, 21:26:27 UTC

Last enriched: 10/10/2026, 21:30:11 UTC

Last updated: 10/11/2026, 04:48:07 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses