4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether brotli is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2025-6176
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
MEDIUM 6.5
CVE-2020-36846
Integer overflow in the bundled Brotli C library
HIGH 7.5
CVE-2025-6176
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
UNKNOWN
CVE-2020-36846
CVE-2020-36846
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes