PT-2026-45899 · Pypi · Dask

Dem0

·

Published

2026-06-03

·

Updated

2026-06-03

·

CVE-2026-10705

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions dask versions prior to 3.1
Description A flaw in the HLL Handler component allows for remote resource consumption. The issue is located within the nunique approx() function in the dask/dataframe/hyperloglog.py file. Exploitation is considered difficult and requires a high degree of complexity.
Recommendations As a temporary workaround, consider restricting the use of the nunique approx() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Resource Release

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-10705

Affected Products

Dask