CVE-2026-105782High· 7.5▾ TwilightScrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler processing the response. This issue is fixed in version 2.14.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
Scrapy >= 1.4.0, <= 2.14.1Patched in:
Scrapy 2.14.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-0577Medium· 6.5Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy
CVE-2026-84366High· 7.4Scrapy is a high-level web crawling and scraping framework for Python
CVE-2021-41125Medium· 5.7Scrapy HTTP authentication credentials potentially leaked to target websites
CVE-2024-3574High· 7.5Scrapy authorization header leakage on cross-domain redirect
CVE-2024-3572High· 7.5Scrapy decompression bomb vulnerability
CVE-2026-61599High· 8.8djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance