CVE-2026-18503EPSS p1.7%
CVE-2026-18503CVE-2026-18503
Description
Attacker-controlled CSV samples can trigger super-linear
regular-expression work during dialect sniffing and consume significant
CPU when applications pass unbounded input to csv.Sniffer.sniff().
Scoring
| EPSS | 0.11% probability of exploitation · percentile 1.7% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-12 |