VDB
CVE-2026-18503
CVE-2026-18503
PUBLISHED
CVSS 2.4 LOW
Reported by PSF · Published August 10, 2026
Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().
Risk Scores
CVSS 4.0
2.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Python Software Foundation | CPython | 0, 3.11.0, 3.12.0 |
| Python Software Foundation | CPython | 0, 3.15.0a1, 3.14.0 |
| wolfi | python-3.11 | 0, 0, 0 |
| chainguard | python-3.12 | 0, 0 |
| wolfi | python-3.12 | 0, 0, 0 |
| wolfi | python-3.10 | 0, 0, 0 |
| chainguard | python-3.11 | 0, 0 |
| chainguard | python-3.10 | 0, 0 |
Timeline
- Aug 10, 2026 CVE Published
- Aug 11, 2026 Coalition ESS Score
- Aug 13, 2026 CVE Updated
- Aug 16, 2026 Security Advisory