2.3 LOW
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): Not Defined (X)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
Activity log
- Created suggestion
dask HLL hyperloglog.py nunique_approx resource consumption
A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.
References
-
VDB-368018 | dask HLL hyperloglog.py nunique_approx resource consumption technical-descriptionvdb-entry
-
-
CVE-2026-10705 | CVE Analysis and Report third-party-advisory
-
https://github.com/dask/dask/issues/12403 issue-tracking
-
-
https://github.com/dask/dask/ product
Affected products
- ==3.0
Matching in nixpkgs
pkgs.python313Packages.dask
Minimal task scheduling abstraction
pkgs.python314Packages.dask
Minimal task scheduling abstraction
pkgs.python313Packages.dask-ml
Scalable Machine Learn with Dask
pkgs.python314Packages.dask-ml
Scalable Machine Learn with Dask
pkgs.python313Packages.dask-glm
Generalized Linear Models with Dask
pkgs.python313Packages.dask-mpi
Deploy Dask using mpi4py
pkgs.python314Packages.dask-glm
Generalized Linear Models with Dask
pkgs.python314Packages.dask-mpi
Deploy Dask using mpi4py
pkgs.python313Packages.dask-yarn
None
-
nixos-26.05 -
- nixos-26.05-small 0.9
pkgs.python314Packages.dask-yarn
None
-
nixos-26.05 -
- nixos-26.05-small 0.9
pkgs.python313Packages.dask-image
Distributed image processing
pkgs.python314Packages.dask-image
Distributed image processing
pkgs.python313Packages.dask-gateway
Client library for interacting with a dask-gateway server
pkgs.python314Packages.dask-gateway
Client library for interacting with a dask-gateway server
pkgs.python313Packages.dask-jobqueue
Deploy Dask on job schedulers like PBS, SLURM, and SGE
pkgs.python314Packages.dask-jobqueue
Deploy Dask on job schedulers like PBS, SLURM, and SGE
pkgs.pkgsRocm.python3Packages.dask-mpi
Deploy Dask using mpi4py
pkgs.python313Packages.dask-gateway-server
Multi-tenant server for securely deploying and managing multiple Dask clusters
pkgs.python314Packages.dask-gateway-server
Multi-tenant server for securely deploying and managing multiple Dask clusters
Package maintainers
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>