Executive brief
t-digest is a data structure library used for computing quantiles and percentiles in streaming and big data applications. A flaw in its deserialization logic allows attackers to inject specially crafted data that causes severe performance degradation during data processing, potentially leading to denial of service in applications that parse untrusted serialized digests.
Technical details
The vulnerability exists in the MergingDigest.fromBytes() deserialization method across t-digest versions 3.1 through 3.3. The flaw fails to validate centroid mean values during deserialization, allowing attackers to craft malicious serialized digests containing NaN (Not-a-Number) centroids. When such a digest is deserialized and subsequently merged, the NaN values bypass validation checks and degrade the internal sorting algorithm's performance from O(n log n) to O(n²), causing severe processing delays. The attack requires network-accessible deserialization of untrusted digest objects but does not require authentication. This is a denial-of-service attack vector.
Affected products
- tdunning t-digest 3.1 through 3.3
Timeline
- 2026-09-09: disclosed