CVE-2026-18503
Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().
- Published Aug 10, 2026
- CVSS 2.4 low
- 0.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available