Scrapy
14 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Scrapy, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Scrapy CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High6
- Medium3
Latest CVEs
The 14 most recently published vulnerabilities affecting Scrapy.
- CVE-2026-84366Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default7.4
- GHSA-cwxj-rr6w-m6w7Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware—
- CVE-2025-6176Brotli decompression bomb DoS in scrapy/scrapy7.5
- CVE-2024-1968Authorization Header Leakage in scrapy/scrapy on Scheme Change Redirects7.5
- GHSA-23j4-mw76-5v7hScrapy allows redirect following in protocols other than HTTP—
- GHSA-jm3v-qxmh-hxwvScrapy's redirects ignoring scheme-specific proxy settings—
- CVE-2024-3574Authorization Header Leak During Cross-Domain Redirect in scrapy/scrapy7.5
- CVE-2024-3572XML External Entity (XXE) Vulnerability in scrapy/scrapy7.5
- CVE-2024-1892ReDoS Vulnerability in scrapy/scrapy's XMLFeedSpider6.5
- GHSA-9x8m-2xpf-crp3Scrapy before 2.6.2 and 1.8.3 vulnerable to one proxy sending credentials to another—
- CVE-2022-0577Exposure of Sensitive Information to an Unauthorized Actor in scrapy/scrapy6.5
- GHSA-mfjm-vh54-3f96Scrapy cookie-setting is not restricted based on the public suffix list—
- CVE-2021-41125HTTP authentication credential leak to target websites in scrapy5.7
- CVE-2017-14158Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the file...7.5
Product grouping is registry-driven, with AI assist and human review. How it works