๐Ÿ” CVE Alert

CVE-2026-46497

UNKNOWN 0.0

SSRF via sitemap-derived URLs in Crawlee for Python

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnerable to SSRF via sitemap-derived URLs. This issue has been patched in version 1.7.0.

CWE CWE-918
Vendor apify
Product crawlee-python
Published Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for apify crawlee-python

Be the first to know when new unknown vulnerabilities affecting apify crawlee-python are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

apify / crawlee-python
>= 1.0.0, < 1.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apify/crawlee-python/security/advisories/GHSA-3r75-xc34-5f44 github.com: https://github.com/apify/crawlee-python/releases/tag/v1.7.0