[CVE-2026-18503] Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
Aug. 10, 2026
1:42 p.m.
There is a LOW severity vulnerability affecting CPython.
Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().
Please see the linked CVE ID for the latest information on affected versions:
37
Age (days ago)
37
Last active (days ago)
0 comments
1 participants
participants (1)
-
Seth Larson