Skip to content
VulniPulse
Highest advisory severityLow 1 vendor · 1 advisory

CVE-2026-18503

CVE-2026-18503: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityLow2.8

    Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff

    CVE-2026-18503Source published Source updated

    Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv. Sniffer.sniff(). A flaw was found in the `csv. This excessive processing consumes significant CPU resources, potentially leading to a Denial of Service (DoS) for applications that process unbounded input using this function. Red Hat has evaluated this issue and determined it has a Low security impact. Most applications are not affected as they use csv.reader() or csv. DictReader() directly without invoking the sniffing functionality. Red Hat severity: Low — CVSS 2.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-1333. Affected Red Hat products: Red Hat Hardened Images; Exploit Intelligence; Red…

    Affected products in this advisory
    • Red Hat Hardened Images
    • Exploit Intelligence
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 6

    12 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • python3-14-main-3.14.7-1.hum1
    • python3-13-main-3.13.15-1.hum1
    • python3-10-main-3.10.21-1.hum1
    • python3-11-main-3.11.16-1.hum1

    6 more entries in the full advisory.

    Mitigation guidance
    • Do not pass untrusted or unbounded CSV input to csv.Sniffer.sniff(). If dialect detection is needed, limit the size of the sample passed to sniff() or use a known dialect directly with csv.reader().

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery