CVE-2026-10705

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en dask hasta la versión 3.0. Se ve afectada por este problema la función nunique_approx del archivo dask/dataframe/hyperloglog.py del componente HLL Gestor. Esta manipulación provoca consumo de recursos. El ataque puede llevarse a cabo de forma remota. Se requiere un alto grado de complejidad para el ataque. Se sabe que la explotación es difícil. La solicitud de extracción para corregir este problema espera aceptación.

03 Jun 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 02:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-10705

Mitre link : CVE-2026-10705

CVE.ORG link : CVE-2026-10705


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption

CWE-404

Improper Resource Shutdown or Release