CVE-2026-105782
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler processing the response. This issue is fixed in version 2.14.2.
| CWE | CWE-470 |
| Vendor | scrapy |
| Product | scrapy |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for scrapy scrapy
Be the first to know when new high vulnerabilities affecting scrapy scrapy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
scrapy / scrapy
>= 1.4.0, < 2.14.2
References
github.com: https://github.com/scrapy/scrapy/security/advisories/GHSA-cwxj-rr6w-m6w7 github.com: https://github.com/scrapy/scrapy/commit/945b787a263586cb5803c01c6da57daad8997ae5 github.com: https://github.com/scrapy/scrapy/commit/b6e5c58ae707a3d4bb491537b5519534050047e0 github.com: https://github.com/scrapy/scrapy/releases/tag/2.14.2