Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp9q-4rh4-m8jc

Опубликовано: 03 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.

EPSS

Процентиль: 21%
0.00287
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.

CVSS3: 3.1
nvd
3 месяца назад

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.

CVSS3: 3.1
debian
3 месяца назад

A flaw has been found in dask up to 3.0. Affected by this issue is the ...

EPSS

Процентиль: 21%
0.00287
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-400