Scrapy allows redirect following in protocols other than HTTP
Modified: 11/28/2024
package
pkg:pypi/scrapy
Scrapy allows redirect following in protocols other than HTTP
Modified: 11/28/2024
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
Modified: 2/4/2026
Scrapy leaks the authorization header on same-domain but cross-origin redirects
Modified: 7/15/2025
Scrapy decompression bomb vulnerability
Modified: 4/16/2024
Scrapy before 2.6.2 and 1.8.3 vulnerable to one proxy sending credentials to another
Modified: 11/28/2024
Scrapy vulnerable to ReDoS via XMLFeedSpider
Modified: 1/14/2025
Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy
Modified: 10/22/2024
Scrapy authorization header leakage on cross-domain redirect
Modified: 4/16/2024
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
Modified: 3/14/2026
Scrapy denial of service vulnerability
Modified: 5/20/2026
Scrapy's redirects ignoring scheme-specific proxy settings
Modified: 11/28/2024
Scrapy HTTP authentication credentials potentially leaked to target websites
Modified: 3/13/2026
Scrapy cookie-setting is not restricted based on the public suffix list
Modified: 12/7/2024
Modified: 10/9/2025
Modified: 11/8/2023
Modified: 10/9/2025
Modified: 6/10/2026
Modified: 6/10/2026