Please do not report security vulnerabilities through public GitHub issues, pull requests or mailing lists.
Report them privately to the Apache Security Team at security@apache.org, or to the Apache DataSketches PMC at private@datasketches.apache.org. Apache DataSketches follows the Apache vulnerability handling process.
Please include the affected component and version, a description of the issue and, if possible, a way to reproduce it (for example, a serialized sketch that triggers it).
The Apache DataSketches PMC supports only the latest release of each component. Security fixes are made in the next release and are not backported. Users should upgrade to the latest release to receive fixes.
All of the following affect only applications that deserialize sketches from untrusted sources. They are fixed in DataSketches C++ 5.3.0.
| CVE | Severity | Description | Affected versions |
|---|---|---|---|
| CVE-2026-103501 | moderate | Heap buffer overflow in HLL sketch deserialization | 1.0.0-incubating through 5.2.0 |
| CVE-2026-103513 | moderate | Out-of-bounds read and write in CPC sketch deserialization | 2.0.0-incubating through 5.2.0 |
| CVE-2026-103634 | moderate | Out-of-bounds read and write in Count-Min sketch deserialization | 4.1.0 through 5.2.0 |
| CVE-2026-103635 | low | Out-of-bounds read in compact Theta sketch deserialization | 3.1.0 through 5.2.0 |
| CVE-2026-103636 | low | Out-of-bounds read in VarOpt union deserialization | 2.0.0-incubating through 5.2.0 |