---
id: CVE-2021-41125
aliases:
  - GHSA-jwqp-28gf-p498
  - PYSEC-2021-363
title: 'Scrapy HTTP authentication credentials potentially leaked to target websites '
summary: 'Scrapy HTTP authentication credentials potentially leaked to target websites '
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'
vendor: scrapy
product: scrapy
ecosystem: pip
affected:
  - scrapy < 1.8.1
  - 'scrapy >= 2.0.0, < 2.5.1'
patched:
  - scrapy 1.8.1
  - scrapy 2.5.1
published: '2021-10-06'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-jwqp-28gf-p498'
references:
  - url: 'https://github.com/scrapy/scrapy/security/advisories/GHSA-jwqp-28gf-p498'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-41125'
  - url: >-
      https://github.com/scrapy/scrapy/commit/b01d69a1bf48060daec8f751368622352d8b85a6
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/scrapy/PYSEC-2021-363.yaml
  - url: 'https://github.com/scrapy/scrapy'
  - url: 'https://lists.debian.org/debian-lts-announce/2022/03/msg00021.html'
  - url: >-
      https://w3lib.readthedocs.io/en/latest/w3lib.html#w3lib.http.basic_auth_header
  - url: >-
      http://doc.scrapy.org/en/latest/topics/downloader-middleware.html#module-scrapy.downloadermiddlewares.httpauth
tags:
  - osv
  - pip
epss: 0.01261
epssPercentile: 0.68348
ingestedAt: '2026-07-08T18:25:50.897Z'
---

## Overview

### Impact

If you use [`HttpAuthMiddleware`](http://doc.scrapy.org/en/latest/topics/downloader-middleware.html#module-scrapy.downloadermiddlewares.httpauth) (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target.

This includes requests generated by Scrapy components, such as `robots.txt` requests sent by Scrapy when the `ROBOTSTXT_OBEY` setting is set to `True`, or as requests reached through redirects.

### Patches

Upgrade to Scrapy 2.5.1 and use the new `http_auth_domain` spider attribute to control which domains are allowed to receive the configured HTTP authentication credentials.

If you are using Scrapy 1.8 or a lower version, and upgrading to Scrapy 2.5.1 is not an option, you may upgrade to Scrapy 1.8.1 instead.

### Workarounds

If you cannot upgrade, set your HTTP authentication credentials on a per-request basis, using for example the [`w3lib.http.basic_auth_header`](https://w3lib.readthedocs.io/en/latest/w3lib.html#w3lib.http.basic_auth_header) function to convert your credentials into a value that you can assign to the `Authorization` header of your request, instead of defining your credentials globally using [`HttpAuthMiddleware`](http://doc.scrapy.org/en/latest/topics/downloader-middleware.html#module-scrapy.downloadermiddlewares.httpauth).

### For more information
If you have any questions or comments about this advisory:
* [Open an issue](https://github.com/scrapy/scrapy/issues)
* [Email us](mailto:opensource@zyte.com)


## Affected packages

- `scrapy < 1.8.1`
- `scrapy >= 2.0.0, < 2.5.1`

## Remediation

Upgrade to a patched release:

- `scrapy 1.8.1`
- `scrapy 2.5.1`
