Dependency scanning
Check whether scrapy is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-84366
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
CVE-2026-84366
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
CVE-2025-6176
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
CVE-2025-6176
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
CVE-2021-41125
Scrapy HTTP authentication credentials potentially leaked to target websites
CVE-2024-3572
Scrapy decompression bomb vulnerability
CVE-2024-3574
Scrapy authorization header leakage on cross-domain redirect
CVE-2024-3572
Scrapy decompression bomb vulnerability
CVE-2024-3574
Scrapy authorization header leakage on cross-domain redirect
CVE-2024-1968
CVE-2024-1968
CVE-2024-1892
CVE-2024-1892
CVE-2017-14158
Scrapy denial of service vulnerability
GHSA-cwxj-rr6w-m6w7
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
CVE-2022-0577
CVE-2022-0577
CVE-2017-14158
CVE-2017-14158
CVE-2024-1968
Scrapy leaks the authorization header on same-domain but cross-origin redirects
CVE-2024-1892
Scrapy vulnerable to ReDoS via XMLFeedSpider
GHSA-mfjm-vh54-3f96
Scrapy cookie-setting is not restricted based on the public suffix list
GHSA-cg34-w3fm-82h3
Duplicate Advisory: Scrapy leaks the authorization header on same-domain but cross-origin redirects
GHSA-23j4-mw76-5v7h
Scrapy allows redirect following in protocols other than HTTP
GHSA-7c9g-vj9m-8pm6
Duplicate Advisory: ReDos vulnerability of XMLFeedSpider
GHSA-9x8m-2xpf-crp3
Scrapy before 2.6.2 and 1.8.3 vulnerable to one proxy sending credentials to another
GHSA-jm3v-qxmh-hxwv
Scrapy's redirects ignoring scheme-specific proxy settings
GHSA-rmqv-7v3j-mr7p
Duplicate Advisory: Scrapy decompression bomb vulnerability
GHSA-4q82-j5c2-g2c5
Duplicate Advisory: Scrapy authorization header leakage on cross-domain redirect
CVE-2022-0577
Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy
CVE-2021-41125
CVE-2021-41125
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes