---
cve: "CVE-2026-18503"
severity: "LOW"
cvss: 2.4
epss: "12%"
vendor: "Python Software Foundation"
kev: false
exploited: false
published: "2026-08-10 13:45:31"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-10T04:19:44+02:00"
---

# CVE-2026-18503

> 2.4 LOW · 🧪 PoC

## Beschreibung

Attacker-controlled CSV samples can trigger super-linear 
regular-expression work during dialect sniffing and consume significant 
CPU when applications pass unbounded input to csv.Sniffer.sniff().

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |

## Patch verfügbar (OSV)

- 3a19c2f0b3e91ce8f23d0cc64d4c9ee557823f24 (Commit)
- 41388c9cb160d0886d5ca00d2e6c8782608a4549 (Commit)

## Referenzen

- <https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/>
- <https://github.com/python/cpython/pull/153694>
- <https://github.com/python/cpython/issues/98820>
- <https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82>
- <https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9>
- <https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a>
- <https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b>
- <https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024>
- <https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-18503) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
