Scrapy
This hub aggregates every CVE we track for Scrapy, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
8
CVEs tracked
0
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 8 most recently published vulnerabilities affecting Scrapy.
- CVE-2025-6176Brotli decompression bomb DoS in scrapy/scrapy7.5
- CVE-2024-1968Authorization Header Leakage in scrapy/scrapy on Scheme Change Redirects7.5
- CVE-2024-3574Authorization Header Leak During Cross-Domain Redirect in scrapy/scrapy7.5
- CVE-2024-3572XML External Entity (XXE) Vulnerability in scrapy/scrapy7.5
- CVE-2024-1892ReDoS Vulnerability in scrapy/scrapy's XMLFeedSpider6.5
- CVE-2022-0577Exposure of Sensitive Information to an Unauthorized Actor in scrapy/scrapy6.5
- CVE-2021-41125HTTP authentication credential leak to target websites in scrapy5.7
- CVE-2017-14158Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the file...7.5
Product normalization is registry-driven with AI assist and human review. How it works