CVE-2026-18503

NameCVE-2026-18503
DescriptionAttacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pypy3 (PTS)bookworm7.3.11+dfsg-2+deb12u3vulnerable
trixie7.3.19+dfsg-2vulnerable
forky, sid7.3.23+dfsg-1vulnerable
python3.11 (PTS)bookworm3.11.2-6+deb12u8vulnerable
bookworm (security)3.11.2-6+deb12u3vulnerable
python3.13 (PTS)trixie3.13.5-2+deb13u3vulnerable
forky, sid3.13.15-1fixed
python3.14 (PTS)forky, sid3.14.7-1fixed
python3.15 (PTS)forky3.15.0~rc1-1fixed
sid3.15.0~rc2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pypy3source(unstable)(unfixed)
python2.7sourcebullseye(unfixed)end-of-life
python2.7source(unstable)(unfixed)
python3.11source(unstable)(unfixed)
python3.13source(unstable)3.13.15-1
python3.14source(unstable)3.14.7-1
python3.15source(unstable)3.15.0~rc1-1
python3.9source(unstable)(unfixed)

Notes

[trixie] - python3.13 <no-dsa> (Minor issue)
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
[trixie] - pypy3 <no-dsa> (Minor issue)
https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/
https://github.com/python/cpython/issues/98820
https://github.com/python/cpython/pull/153694
Fixed by: https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9 (v3.15.0rc1)
Fixed by: https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a (v3.14.7)
Fixed by: https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b (v3.13.15)
Fixed by: https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82 (v3.12.14)
Fixed by: https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024 (v3.11.16)
Fixed by: https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4 (v3.10.21)

Search for package or bug name: Reporting problems