CVE-2026-103513

UNRATEDCVSS · not yet scoredTrending — 4 sources updated this week
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: —CVSS v2: —Exploit: None knownExposed services: Not assessed

The CVE record names the fixed release — apply it.

Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp).

A crafted serialized CPC sketch passed to cpc_sketch::deserialize(), from either a byte buffer or a stream, can cause the decompressor to read past the end of the compressed data, because the read position was only checked after decoding finished. In the hybrid flavor, it can also cause a write outside an internal heap buffer, because decoded row indices were not validated. Several other header fields and decoded values, including lg_k, were also not validated. This can corrupt heap memory, causing a crash and potentially enabling further exploitation.

This issue affects Apache DataSketches C++: from 2.0.0-incubating before 5.3.0. Only applications that deserialize CPC sketches from untrusted sources are affected.

Users are recommended to upgrade to version 5.3.0, which fixes this issue.

CVSS v3
—
EchelonGraph score
Not yet assessedNo source has published severity data for this CVE yet — no CVSS score from NVD or a CNA, no GitHub advisory, and it is not in CISA KEV. This is not a rating of zero; we cannot assess it yet.
EG Score
—
EG Risk
—
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

October 10, 2026

Last Modified

October 10, 2026

Vendor Advisories for CVE-2026-103513(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Weakness Classification(2)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 4× in last 7d / 4× in last 30d)

Each row is a time one of our pipelines fetched, updated or re-scored this CVE. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. An arrow marks a change the record states ("CVSS v3 → 9.1"); EPSS and GHSA rows show the values recorded at that time, not what changed (EPSS values are rounded; hover one for the exact figures). Most recent first.

  1. 2026-10-10 13:23 UTCGHSA enrichmentGHSA-2w73-5h25-v3cg
  2. 2026-10-10 11:20 UTCNVD update
  3. 2026-10-10 10:37 UTCEG score recompute
  4. 2026-10-10 10:35 UTCMITRE cvelistV5first tracked

Frequently asked(3)

What is CVE-2026-103513?
CVE-2026-103513 is a publicly disclosed vulnerability published on October 10, 2026. Out-of-bounds read and write in the CPC sketch deserialization of Apache DataSketches C++ (repo: datasketches-cpp). A crafted serialized CPC sketch passed to cpcsketch::deserialize(), from either a byte buffer or a stream, can cause the decompressor to read past the end of the compressed data,…
When was the CVE record for CVE-2026-103513 published?
The CVE record for CVE-2026-103513 was published on October 10, 2026. That is the record's publication date; the vulnerability itself may have been made public earlier. EchelonGraph's copy of the record carries a last-modified date of October 10, 2026; the record at its source may have been updated since.
How do I remediate CVE-2026-103513?
The CVE record for CVE-2026-103513 names the fix: "Users are recommended to upgrade to version 5.3.0, which fixes this issue." The vendor advisories EchelonGraph has for CVE-2026-103513 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-103513

Explore →

Is Your Infrastructure Affected by CVE-2026-103513?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.