CVE-2026-18503

Published: August 14, 2026Last modified: August 25, 2026

Description

Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpython3Fixed (3.11.16-r0)
25 LTSpython3Fixed (3.12.14-r0)
Streampython3Unknown (3.11.4-r0)
Hardened Containers23 LTSpython3Fixed (3.11.16-r0)
25 LTSpython3Fixed (3.12.14-r0)
Streampython3Unknown (3.11.4-r0)

References

ON THIS PAGE