7.5
CVE-2026-105782
- EPSS 0.38%
- Veröffentlicht 05.10.2026 23:08:55
- Zuletzt bearbeitet 06.10.2026 16:00:36
- Erkennungen
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler processing the response. This issue is fixed in version 2.14.2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerscrapy
≫
Produkt
scrapy
Version
>= 1.4.0, < 2.14.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.296 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.
https://github.com/scrapy/scrapy/security/advisories/GHSA-cwxj-rr6w-m6w7
https://github.com/scrapy/scrapy/commit/945b787a263586cb5803c01c6da57daad8997ae5
https://github.com/scrapy/scrapy/commit/b6e5c58ae707a3d4bb491537b5519534050047e0
https://github.com/scrapy/scrapy/releases/tag/2.14.2