Apache DataSketches C++ 5.3.0 Hardens Five Deserialization Paths
Quick Answer
Apache DataSketches C++ 5.3.0 fixes five low-to-moderate deserialization vulnerabilities: CVE-2026-103501, CVE-2026-103513, CVE-2026-103634, CVE-2026-103635, and CVE-2026-103636. Applications that deserialize affected sketch formats from untrusted sources should upgrade to 5.3.0 or later.
Upgrade Untrusted-Sketch Consumers To DataSketches C++ 5.3.0
What to do now: Inventory applications and services that deserialize DataSketches C++ input, identify untrusted or cross-boundary sketch sources, upgrade affected builds through 5.2.0 to 5.3.0 or later, validate serialized-data compatibility and error handling, and retain evidence.
Last verified: 2026-10-10 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Apache DataSketches C++ |
|---|---|
| Advisory | CVE-2026-103501 / CVE-2026-103513 / CVE-2026-103634 / CVE-2026-103635 / CVE-2026-103636 / Apache DataSketches C++ 5.3.0 |
| CVEs | CVE-2026-103501, CVE-2026-103513, CVE-2026-103634, CVE-2026-103635, CVE-2026-103636 |
| Authoritative release date | 2026-10-10 10:23:58.547 UTC; latest initial Apache CNA advisory in the grouped disclosure |
| Authority revision date | 2026-10-10 12:10:56.008 UTC; latest Apache CNA revision in the grouped disclosure |
| Affected versions | Applications using Apache DataSketches C++ 1.0.0-incubating through 5.2.0 that deserialize the affected HLL, CPC, Count-Min, compact Theta, or VarOpt sketch formats from untrusted sources; the starting affected release varies by sketch type. |
| Fixed version | Apache DataSketches C++ 5.3.0 or later |
| CVSS base score | Not provided by the authority |
| CVSS severity | Low to Moderate |
| Exploitation status | Not stated by the Apache Software Foundation; no exploitation claim is inferred. |
What Changed
Apache DataSketches C++ 5.3.0 adds bounds, size, header, and decoded-value validation across five sketch deserialization paths. Crafted or truncated sketches can trigger out-of-bounds reads or writes, heap corruption, crashes, and in some cases exposure of adjacent memory. Apache states that only applications deserializing sketches from untrusted sources are affected.
What To Validate Now
- Inventory. Locate direct and transitive Apache DataSketches C++ use, record the deployed version, sketch families, serialized-data producers, trust boundaries, network or file ingestion paths, and owners.
- Establish applicability. Prioritize applications that deserialize HLL, CPC, Count-Min, compact Theta, or VarOpt sketches from untrusted sources. Match the advisory-specific starting versions and do not infer exposure solely from linking the library.
- Remediate. Upgrade to Apache DataSketches C++ 5.3.0 or later through the supported build and dependency process. If immediate upgrade is impossible, block or strictly control untrusted serialized sketch input while preparing the update.
- Validate. Confirm the resolved library version in built and deployed artifacts, test valid and malformed serialized sketches, verify cross-language compatibility where used, monitor crashes and parser errors, and exercise rollback.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Version 5.3.0 includes serialization and compatibility changes in addition to security hardening. Test persisted and cross-language sketch images before broad rollout, preserve representative data and logs, and do not treat a crash or malformed input as proof of exploitation.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
- CVE-2026-103501
- CVE-2026-103513
- CVE-2026-103634
- CVE-2026-103635
- CVE-2026-103636
- Apache DataSketches C++ 5.3.0
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

