CVE-2026-18503EPSS p1.6%

CVE-2026-18503CVE-2026-18503

Description

Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().

Scoring

EPSS0.12% probability of exploitation · percentile 1.6% · 2026-10-05T12:00:23Z
Last modified2026-08-18
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.