{"id":"CVE-2021-41125","aliases":["GHSA-jwqp-28gf-p498","PYSEC-2021-363"],"title":"Scrapy HTTP authentication credentials potentially leaked to target websites ","summary":"Scrapy HTTP authentication credentials potentially leaked to target websites ","severity":"medium","cvss":5.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","vendor":"scrapy","product":"scrapy","ecosystem":"pip","affected":["scrapy < 1.8.1","scrapy >= 2.0.0, < 2.5.1"],"patched":["scrapy 1.8.1","scrapy 2.5.1"],"published":"2021-10-06","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jwqp-28gf-p498","references":[{"url":"https://github.com/scrapy/scrapy/security/advisories/GHSA-jwqp-28gf-p498"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41125"},{"url":"https://github.com/scrapy/scrapy/commit/b01d69a1bf48060daec8f751368622352d8b85a6"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/scrapy/PYSEC-2021-363.yaml"},{"url":"https://github.com/scrapy/scrapy"},{"url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00021.html"},{"url":"https://w3lib.readthedocs.io/en/latest/w3lib.html#w3lib.http.basic_auth_header"},{"url":"http://doc.scrapy.org/en/latest/topics/downloader-middleware.html#module-scrapy.downloadermiddlewares.httpauth"}],"tags":["osv","pip"],"epss":0.01261,"epssPercentile":0.68343,"ingestedAt":"2026-07-08T18:25:50.897Z","slug":"CVE-2021-41125","body":"## Overview\n\n### Impact\n\nIf you use [`HttpAuthMiddleware`](http://doc.scrapy.org/en/latest/topics/downloader-middleware.html#module-scrapy.downloadermiddlewares.httpauth) (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target.\n\nThis includes requests generated by Scrapy components, such as `robots.txt` requests sent by Scrapy when the `ROBOTSTXT_OBEY` setting is set to `True`, or as requests reached through redirects.\n\n### Patches\n\nUpgrade to Scrapy 2.5.1 and use the new `http_auth_domain` spider attribute to control which domains are allowed to receive the configured HTTP authentication credentials.\n\nIf you are using Scrapy 1.8 or a lower version, and upgrading to Scrapy 2.5.1 is not an option, you may upgrade to Scrapy 1.8.1 instead.\n\n### Workarounds\n\nIf you cannot upgrade, set your HTTP authentication credentials on a per-request basis, using for example the [`w3lib.http.basic_auth_header`](https://w3lib.readthedocs.io/en/latest/w3lib.html#w3lib.http.basic_auth_header) function to convert your credentials into a value that you can assign to the `Authorization` header of your request, instead of defining your credentials globally using [`HttpAuthMiddleware`](http://doc.scrapy.org/en/latest/topics/downloader-middleware.html#module-scrapy.downloadermiddlewares.httpauth).\n\n### For more information\nIf you have any questions or comments about this advisory:\n* [Open an issue](https://github.com/scrapy/scrapy/issues)\n* [Email us](mailto:opensource@zyte.com)\n\n\n## Affected packages\n\n- `scrapy < 1.8.1`\n- `scrapy >= 2.0.0, < 2.5.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `scrapy 1.8.1`\n- `scrapy 2.5.1`","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.4,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}