Apache DataSketches C++ 5.3.0 Hardens Five Deserialization Paths

P2 — VALIDATE AND UPDATELow to Moderate · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

Apache DataSketches C++ 5.3.0 fixes five low-to-moderate deserialization vulnerabilities: CVE-2026-103501, CVE-2026-103513, CVE-2026-103634, CVE-2026-103635, and CVE-2026-103636. Applications that deserialize affected sketch formats from untrusted sources should upgrade to 5.3.0 or later.

Upgrade Untrusted-Sketch Consumers To DataSketches C++ 5.3.0

What to do now: Inventory applications and services that deserialize DataSketches C++ input, identify untrusted or cross-boundary sketch sources, upgrade affected builds through 5.2.0 to 5.3.0 or later, validate serialized-data compatibility and error handling, and retain evidence.

Open the authoritative advisory

Last verified: 2026-10-10 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeApache DataSketches C++
AdvisoryCVE-2026-103501 / CVE-2026-103513 / CVE-2026-103634 / CVE-2026-103635 / CVE-2026-103636 / Apache DataSketches C++ 5.3.0
CVEsCVE-2026-103501, CVE-2026-103513, CVE-2026-103634, CVE-2026-103635, CVE-2026-103636
Authoritative release date2026-10-10 10:23:58.547 UTC; latest initial Apache CNA advisory in the grouped disclosure
Authority revision date2026-10-10 12:10:56.008 UTC; latest Apache CNA revision in the grouped disclosure
Affected versionsApplications using Apache DataSketches C++ 1.0.0-incubating through 5.2.0 that deserialize the affected HLL, CPC, Count-Min, compact Theta, or VarOpt sketch formats from untrusted sources; the starting affected release varies by sketch type.
Fixed versionApache DataSketches C++ 5.3.0 or later
CVSS base scoreNot provided by the authority
CVSS severityLow to Moderate
Exploitation statusNot stated by the Apache Software Foundation; no exploitation claim is inferred.

What Changed

Apache DataSketches C++ 5.3.0 adds bounds, size, header, and decoded-value validation across five sketch deserialization paths. Crafted or truncated sketches can trigger out-of-bounds reads or writes, heap corruption, crashes, and in some cases exposure of adjacent memory. Apache states that only applications deserializing sketches from untrusted sources are affected.

What To Validate Now

  1. Inventory. Locate direct and transitive Apache DataSketches C++ use, record the deployed version, sketch families, serialized-data producers, trust boundaries, network or file ingestion paths, and owners.
  2. Establish applicability. Prioritize applications that deserialize HLL, CPC, Count-Min, compact Theta, or VarOpt sketches from untrusted sources. Match the advisory-specific starting versions and do not infer exposure solely from linking the library.
  3. Remediate. Upgrade to Apache DataSketches C++ 5.3.0 or later through the supported build and dependency process. If immediate upgrade is impossible, block or strictly control untrusted serialized sketch input while preparing the update.
  4. Validate. Confirm the resolved library version in built and deployed artifacts, test valid and malformed serialized sketches, verify cross-language compatibility where used, monitor crashes and parser errors, and exercise rollback.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Version 5.3.0 includes serialization and compatibility changes in addition to security hardening. Test persisted and cross-language sketch images before broad rollout, preserve representative data and logs, and do not treat a crash or malformed input as proof of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.