© 2025-2026 PySpect
First version without a known vulnerability: 2.16.0
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
Fixed in: 2.14.2
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
Fixed in: 1.2.0, 2.13.4
Scrapy allows redirect following in protocols other than HTTP
Fixed in: 2.11.2
Scrapy's redirects ignoring scheme-specific proxy settings
Fixed in: 2.11.2
Scrapy leaks the authorization header on same-domain but cross-origin redirects
Fixed in: 2.11.2, 1d0502f25bbe55a22899af915623fda1aaeb9dd8, 2.0.0
Scrapy decompression bomb vulnerability
Fixed in: 2.11.1, 1.8.4
Scrapy authorization header leakage on cross-domain redirect
Fixed in: 2.11.1, 1.8.4
Scrapy vulnerable to ReDoS via XMLFeedSpider
Fixed in: 2.11.1, 1.8.4, 479619b340f197a8f24c5db45bc068fb8755f2c5
Scrapy before 2.6.2 and 1.8.3 vulnerable to one proxy sending credentials to another
Fixed in: 1.8.3, 2.6.2
Scrapy denial of service vulnerability
Scrapy cookie-setting is not restricted based on the public suffix list
Fixed in: 1.8.2, 2.6.0
Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy
Fixed in: 1.8.2, 2.6.1, 8ce01b3b76d4634f55067d6cfdf632ec70ba304a
Scrapy HTTP authentication credentials potentially leaked to target websites
Fixed in: 1.8.1, 2.5.1, b01d69a1bf48060daec8f751368622352d8b85a6