Scrapy
7 known vulnerabilities
Top Products
In scrapy/scrapy, an issue was identified where the Authorization header is not removed during redirects that only chang
In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server auth
The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy proj
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_u
Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily
Frequently Asked Questions
How many CVEs affect Scrapy?
Scrapy has 7 CVE records in our database, including 0 critical and 4 high severity vulnerabilities.
What are the most severe Scrapy vulnerabilities?
Scrapy has 0 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Scrapy vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Scrapy products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Scrapy Vulnerabilities
CyberStrike scans your infrastructure for Scrapy vulnerabilities and provides real-time remediation guidance.
Get Started