CVE-2026-18503
CVE-2026-18503: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityLow2.8
Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff
CVE-2026-18503Source published Source updated
Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv. Sniffer.sniff(). A flaw was found in the `csv. This excessive processing consumes significant CPU resources, potentially leading to a Denial of Service (DoS) for applications that process unbounded input using this function. Red Hat has evaluated this issue and determined it has a Low security impact. Most applications are not affected as they use csv.reader() or csv. DictReader() directly without invoking the sniffing functionality. Red Hat severity: Low — CVSS 2.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-1333. Affected Red Hat products: Red Hat Hardened Images; Exploit Intelligence; Red…
- Affected products in this advisory
- Red Hat Hardened Images
- Exploit Intelligence
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
12 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- python3-14-main-3.14.7-1.hum1
- python3-13-main-3.13.15-1.hum1
- python3-10-main-3.10.21-1.hum1
- python3-11-main-3.11.16-1.hum1
6 more entries in the full advisory.
- Mitigation guidance
- Do not pass untrusted or unbounded CSV input to csv.Sniffer.sniff(). If dialect detection is needed, limit the size of the sample passed to sniff() or use a known dialect directly with csv.reader().
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.