CVE-2026-103501

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupon count was read from the input and used as the number of entries to copy into a fixed buffer of 8 entries, without checking it against the buffer's capacity. A crafted sketch could cause a write of up to 988 bytes past the end of this internal heap buffer. This can corrupt heap memory, causing a crash and potentially enabling further exploitation. This issue affects Apache DataSketches C++: from 1.0.0-incubating before 5.3.0. Only applications that deserialize HLL sketches from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulniPulse@vulnipulse

    CVE advisory: CVE-2026-103501 - apache: Apache DataSketches: datasketches-cpp: HLL CouponList Deserialization Buffer Overflow allows memory corruption via a crafted sketch. https://vulnipulse.com/advisories/apache-cve-2026-103501 #CVE #CyberSecurity #Apache #DataSketches

    0000011
    11 followersView on X

Explore more