CVE-2026-18503
EUVD-2026-5563010.08.2026, 14:17
Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python | cpython | 𝑥 < 3.13.15 | CNA |
| python | cpython | 3.14.0 ≤ 𝑥 < 3.14.7 | CNA |
Common Weakness Enumeration
References