Resource Consumption Vulnerability in Dask by Dask Development Team
CVE-2026-10705

2.3LOW

Key Information:

Status
Vendor
CVE Published:
3 June 2026

What is CVE-2026-10705?

A vulnerability exists in Dask, specifically within the nunique_approx function located in the hyperloglog.py file. This flaw can lead to excessive resource consumption, making it a potential target for remote attacks. Although exploiting this vulnerability requires a high level of complexity, it poses risks associated with denial of service. The team is aware of the issue and a pull request to address the flaw is currently pending acceptance.

Affected Version(s)

dask 3.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dem0 (VulDB User)
VulDB CNA Team
.