Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
A vulnerability in Python's csv.Sniffer.sniff() function can cause excessive CPU consumption when processing specially crafted CSV input due to super-linear regular expression complexity. This may lead to a denial of service (DoS) condition. The issue affects Red Hat Hardened Images RPMs containing Python 3.10 packages. Most applications are not affected as they do not use the sniff() function on untrusted input. Red Hat has released updated RPMs to address this issue.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18503 is a denial of service vulnerability caused by inefficient regular expression processing in the csv.Sniffer.sniff() function of Python 3.10. An attacker can supply specially crafted CSV samples that trigger super-linear regex backtracking during dialect sniffing, resulting in high CPU usage. Red Hat identified this issue in their Hardened Images RPMs containing Python 3.10 packages and issued an update to python3.10-3.10.21-1.hum1 and related packages for aarch64 and x86_64 architectures. The vulnerability has low severity and limited impact since most applications do not invoke sniff() on untrusted or unbounded input.
Potential Impact
The vulnerability can cause denial of service by consuming excessive CPU resources when processing maliciously crafted CSV input with the csv.Sniffer.sniff() function. There is no impact on confidentiality or integrity. The issue is rated low severity by Red Hat. Most applications are unaffected as they use csv.reader() or csv.DictReader() without sniffing. The impact is limited to applications that invoke sniff() on untrusted or large CSV samples.
Mitigation Recommendations
Red Hat has released updated python3.10 packages (version 3.10.21-1.hum1) that fix this issue. Users should apply these updates to mitigate the vulnerability. If updating is not immediately possible, avoid passing untrusted or unbounded CSV input to csv.Sniffer.sniff(). Limit the size of the sample passed to sniff() or use a known CSV dialect directly with csv.reader().
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:57010
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a870a56acd9273b49b58636
Added to database: 08/20/2026, 14:08:22 UTC
Last enriched: 09/11/2026, 04:47:37 UTC
Last updated: 10/05/2026, 06:48:14 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.