CVE-2026-18503CWE-1176
CVE-2026-18503
published August 10, 2026
What it is
Attacker-controlled CSV samples can trigger super-linear
regular-expression work during dialect sniffing and consume significant
CPU when applications pass unbounded input to csv.Sniffer.sniff().
The record
Technical detail
- CVSS
- 2.4 · NONE
- CVSS v4.0
- Not supplied
- EPSS
- 0.00119 · 2.0th percentile
- Weakness
- CWE-1176 · Inefficient CPU Computation
- Published
- 2026-08-10T18:17Z
References (9)
EPSS history
Timeline