Disclosure summary
Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking that only 8 bytes were available, so a truncated serialized union could cause a read of up to 24 bytes past the end of the input. For such inputs, the size remaining for the embedded sketch was also computed by an unsigned subtraction that could wrap around, so the embedded sketch's own size checks no longer limited reads to the input. The bytes read can become part of the deserialized union's state. This can cause a crash (denial of service) and could expose adjacent memory contents. This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deserialize VarOpt unions from untrusted sources are affected. Users are recommended to upgrade to version 5.3.0, which fixes this issue.
Source-reported weakness categories
CWE-125, CWE-191
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
CVEProject/cvelistV5 releases · RSS-2b11a7e1dade072c26c14342ed52b8ffeb8
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_2300Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-f946067cb6a34653c12f3a7d3e105773b0f
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_2200Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-7c1aa4e02ee105026a9d5ef835739da2231
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_2100Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-5daad76275e9590636f1bfed69854f874d0
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_2000Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-f5a41e504aba4034d4f99f9de25577fb6a1
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_1900Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-f5dee9e139662097b84b17b3e74d5544c25
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_1800Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-6729502a4ea3125ddd379f75d3eb8cb63a6
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_1700Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-a10ecc85ff20aad80a7e8436dd92befdcfc
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_1600Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-5f26de48c2d7605f54c0980f1221b67644b
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_1500Z
CVE mention in publisher metadata; check the original affected versions.
CVEProject/cvelistV5 releases · RSS-95eb7d8256449b8a75dc66291b65bfe37a2
Open original source · Updated Oct 10, 2026
CVE 2026-10-10_1400Z
CVE mention in publisher metadata; check the original affected versions.
NIST National Vulnerability Database · NVD-CVE-2026-103636
Open original source · Updated Oct 10, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-10T07:17:36-04:00
MODIFIED 2026-10-10T09:17:31-04:00
INGESTED 2026-10-10T20:55:17-04:00