VYPR

datasketches-cpp

by Apache

CVEs (4)

  • CVE-2026-103636Oct 10, 2026
    risk 0.00cvss —epss —

    Out-of-bounds read in the VarOpt union deserialization of Apache DataSketches C++ (repo: datasketches-cpp). var_opt_union::deserialize() read the 32-byte preamble of a non-empty union after checking that only 8 bytes were available, so a truncated serialized union could cause a…

  • CVE-2026-103635Oct 10, 2026
    risk 0.00cvss —epss —

    Out-of-bounds read in the compact Theta sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). compact_theta_sketch::deserialize() and wrapped_compact_theta_sketch::wrap() read header fields before checking that the input was long enough. For the compressed…

  • CVE-2026-103513Oct 10, 2026
    risk 0.00cvss —epss —

    Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). A crafted serialized CPC sketch passed to cpc_sketch::deserialize(), from either a byte buffer or a stream, can cause the decompressor to read past the end of the…

  • CVE-2026-103501Oct 10, 2026
    risk 0.00cvss —epss —

    Heap buffer overflow in the HLL sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). When deserializing a sketch in LIST mode, from either a byte buffer or a stream, the coupon count was read from the input and used as the number of entries to copy into a…