CVE-2026-18503: Python Software Foundation Cpython
Low severity, CVSS 2.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().
Affected products
- Python Software Foundation Cpython: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.15 (fixed in 3.13.15); from 3.14.0, before 3.14.7 (fixed in 3.14.7); from 3.15.0a1, before 3.15.0rc1 (fixed in 3.15.0rc1)
Published 2026-08-10. Last modified 2026-08-18.