GHSA-qp9q-4rh4-m8jcLowCVSS 3.1
A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of...
🔗 CVE IDs covered (1)
📋 Description
A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-10705
- https://github.com/dask/dask/issues/12403
- https://github.com/dask/dask/pull/12401
- https://github.com/dask/dask
- https://vuldb.com/cve/CVE-2026-10705
- https://vuldb.com/submit/831411
- https://vuldb.com/vuln/368018
- https://vuldb.com/vuln/368018/cti
- https://github.com/advisories/GHSA-qp9q-4rh4-m8jc