Vulnerable Library - dask-2024.7.0-py3-none-any.whl
Parallel PyData with Task Scheduling
Library home page: https://files.pythonhosted.org/packages/c6/c7/79f6ae51b64c20db98100946544a47a20671e589be19404f6696481d6024/dask-2024.7.0-py3-none-any.whl
Path to dependency file: /tmp/ws-scm/edit-osm-add-missing-bridge-for-truck-restriction/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260209171136_UUVOOL/python_GCEZEJ/202602091711391/env/lib/python3.9/site-packages/dask-2024.7.0.dist-info
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (dask version) |
Remediation Possible** |
| CVE-2026-10705 |
Low |
3.1 |
dask-2024.7.0-py3-none-any.whl |
Direct |
N/A |
❌ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-10705
Vulnerable Library - dask-2024.7.0-py3-none-any.whl
Parallel PyData with Task Scheduling
Library home page: https://files.pythonhosted.org/packages/c6/c7/79f6ae51b64c20db98100946544a47a20671e589be19404f6696481d6024/dask-2024.7.0-py3-none-any.whl
Path to dependency file: /tmp/ws-scm/edit-osm-add-missing-bridge-for-truck-restriction/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260209171136_UUVOOL/python_GCEZEJ/202602091711391/env/lib/python3.9/site-packages/dask-2024.7.0.dist-info
Dependency Hierarchy:
- ❌ dask-2024.7.0-py3-none-any.whl (Vulnerable Library)
Found in base branch: main
Vulnerability Details
A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.
Publish Date: 2026-06-03
URL: CVE-2026-10705
CVSS 3 Score Details (3.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Step up your Open Source Security Game with Mend here
Parallel PyData with Task Scheduling
Library home page: https://files.pythonhosted.org/packages/c6/c7/79f6ae51b64c20db98100946544a47a20671e589be19404f6696481d6024/dask-2024.7.0-py3-none-any.whl
Path to dependency file: /tmp/ws-scm/edit-osm-add-missing-bridge-for-truck-restriction/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260209171136_UUVOOL/python_GCEZEJ/202602091711391/env/lib/python3.9/site-packages/dask-2024.7.0.dist-info
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - dask-2024.7.0-py3-none-any.whl
Parallel PyData with Task Scheduling
Library home page: https://files.pythonhosted.org/packages/c6/c7/79f6ae51b64c20db98100946544a47a20671e589be19404f6696481d6024/dask-2024.7.0-py3-none-any.whl
Path to dependency file: /tmp/ws-scm/edit-osm-add-missing-bridge-for-truck-restriction/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260209171136_UUVOOL/python_GCEZEJ/202602091711391/env/lib/python3.9/site-packages/dask-2024.7.0.dist-info
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The pull request to fix this issue awaits acceptance.
Publish Date: 2026-06-03
URL: CVE-2026-10705
CVSS 3 Score Details (3.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here