CVE-2026-18503CWE-1176

CVE-2026-18503

published August 10, 2026

CVSS
2.4
EPSS
0%
Percentile
2.0
In the wild
Unconfirmed
What it is

Attacker-controlled CSV samples can trigger super-linear

regular-expression work during dialect sniffing and consume significant

CPU when applications pass unbounded input to csv.Sniffer.sniff().

The record
Technical detail
CVSS
2.4 · NONE
CVSS v4.0
Not supplied
EPSS
0.00119 · 2.0th percentile
Weakness
CWE-1176 · Inefficient CPU Computation
Published
2026-08-10T18:17Z
References (9)
EPSS history
Timeline
  • 10 AUG 13:45Z
    Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
    cvelistv5