Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-10705

Опубликовано: 03 июн. 2026
Источник: debian
EPSS Низкий

Описание

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
daskunfixedpackage
daskno-dsatrixiepackage
daskno-dsabookwormpackage
daskpostponedbullseyepackage

Примечания

  • https://github.com/dask/dask/issues/12403

  • https://github.com/dask/dask/pull/12401

EPSS

Процентиль: 21%
0.00287
Низкий

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.

CVSS3: 3.1
nvd
3 месяца назад

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.

CVSS3: 3.1
github
3 месяца назад

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 21%
0.00287
Низкий