Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().
CVSS Details
- CVSS 4.0 Base Score: 2.4 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade python3.14-freethreading-libsUpgrade python3.12-debugUpgrade python3.13-freethreadingUpgrade python3.12-tkinterUpgrade python3.14-idleUpgrade python3.13Upgrade python3.14-freethreading-develUpgrade python3.12-libsUpgrade python3.12-develUpgrade python3.13-idleUpgrade python3.13-testUpgrade python3.14Upgrade python3.14-freethreading-testUpgrade python3.12-debugsourceUpgrade python3.14-debugsourceUpgrade python3.13-libsUpgrade python3.13-debugsourceUpgrade python3.11-debugUpgrade python3.13-debugUpgrade python3.14-freethreading-debugUpgrade python3.11Upgrade python3.12-idleUpgrade python3.11-tkinterUpgrade python3.14-freethreadingUpgrade python3.13-debuginfoUpgrade python3.11-testUpgrade python3.11-develUpgrade python3.14-testUpgrade python3.12Upgrade python3.11-idleUpgrade python3.13-freethreading-debugUpgrade python3.14-debugUpgrade python3.14-tkinterUpgrade python3.14-freethreading-tkinterUpgrade python3.12-testUpgrade python3.13-develUpgrade python3.12-debuginfoUpgrade python3.11-libsUpgrade python3.14-libsUpgrade python3.13-tkinterUpgrade python3.14-freethreading-idleUpgrade python3.11-debugsourceUpgrade python3.14-develUpgrade python3.14-debuginfoUpgrade python3.11-debuginfo | Sep 1, 2026 | Aug 10, 2026 |
| Redhat_linux | — | No solution exists | Aug 21, 2026 | Aug 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub