Scrapy is a lightweight, narrowly scoped web-scraping and crawling framework whose vulnerability footprint concentrates on input-handling and authorization issues within a single product. The recurring weakness classes—including sensitive information exposure, improper handling of compressed data, authorization flaws, and regex complexity—reflect both the framework's role parsing untrusted web content and common application-layer logic errors in data extraction pipelines. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scrapy over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0577MEDIUM Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1. | Mar 2, 2022 | 6.5 | 25 | NO | NO |
CVE-2017-14158HIGH Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially proble | Sep 5, 2017 | 7.5 | 24 | NO | NO |
CVE-2024-1968HIGH In scrapy/scrapy, an issue was identified where the Authorization header is not removed during redirects that only change the scheme (e.g., HTTPS to HTTP) but remain within the sam | May 20, 2024 | 7.5 | 23 | NO | NO |
CVE-2021-41125MEDIUM Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authenticat | Oct 6, 2021 | 6.5 | 23 | NO | NO |
CVE-2024-3574HIGH In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-d | Apr 16, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-3572HIGH The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This | Apr 16, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-1892MEDIUM A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting | Feb 28, 2024 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scrapy.
Media articles that mention a CVE ID that affects a product developed by Scrapy — matched by CVE ID, not by vendor name.