Scrapy
This hub aggregates every CVE we track for Scrapy, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
14
CVEs tracked
0
Critical
6
High
0
In CISA KEV
Severity distribution
HIGH6MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
1
0
0
0
0
0
1
2024-102026-09
Latest CVEs
The 14 most recently published vulnerabilities affecting Scrapy.
- CVE-2026-84366Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default7.4
- GHSA-cwxj-rr6w-m6w7Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
- CVE-2025-6176Brotli decompression bomb DoS in scrapy/scrapy7.5
- CVE-2024-1968Authorization Header Leakage in scrapy/scrapy on Scheme Change Redirects7.5
- GHSA-23j4-mw76-5v7hScrapy allows redirect following in protocols other than HTTP
- GHSA-jm3v-qxmh-hxwvScrapy's redirects ignoring scheme-specific proxy settings
- CVE-2024-3574Authorization Header Leak During Cross-Domain Redirect in scrapy/scrapy7.5
- CVE-2024-3572XML External Entity (XXE) Vulnerability in scrapy/scrapy7.5
- CVE-2024-1892ReDoS Vulnerability in scrapy/scrapy's XMLFeedSpider6.5
- GHSA-9x8m-2xpf-crp3Scrapy before 2.6.2 and 1.8.3 vulnerable to one proxy sending credentials to another
- CVE-2022-0577Exposure of Sensitive Information to an Unauthorized Actor in scrapy/scrapy6.5
- GHSA-mfjm-vh54-3f96Scrapy cookie-setting is not restricted based on the public suffix list
- CVE-2021-41125HTTP authentication credential leak to target websites in scrapy5.7
- CVE-2017-14158Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the file...7.5
Product normalization is registry-driven with AI assist and human review. How it works