Security

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests or mailing lists.

Report them privately to the Apache Security Team at security@apache.org, or to the Apache DataSketches PMC at private@datasketches.apache.org. Apache DataSketches follows the Apache vulnerability handling process.

Please include the affected component and version, a description of the issue and, if possible, a way to reproduce it (for example, a serialized sketch that triggers it).

Supported Versions

The Apache DataSketches PMC supports only the latest release of each component. Security fixes are made in the next release and are not backported. Users should upgrade to the latest release to receive fixes.

Published Vulnerabilities

DataSketches C++

All of the following affect only applications that deserialize sketches from untrusted sources. They are fixed in DataSketches C++ 5.3.0.

CVE Severity Description Affected versions
CVE-2026-103501 moderate Heap buffer overflow in HLL sketch deserialization 1.0.0-incubating through 5.2.0
CVE-2026-103513 moderate Out-of-bounds read and write in CPC sketch deserialization 2.0.0-incubating through 5.2.0
CVE-2026-103634 moderate Out-of-bounds read and write in Count-Min sketch deserialization 4.1.0 through 5.2.0
CVE-2026-103635 low Out-of-bounds read in compact Theta sketch deserialization 3.1.0 through 5.2.0
CVE-2026-103636 low Out-of-bounds read in VarOpt union deserialization 2.0.0-incubating through 5.2.0