Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105782— Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware

Quick assessment

Affected
scrapy scrapy
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Scrapy 是一个面向 Python 的高级网络爬虫和网页数据采集框架。在版本 1.4.0 至 2.14.2 之间,Scrapy 的 (位于 )存在安全漏洞:当解析 HTTP 响应头中的 字段时,如果其值类似于 Python 模块导入路径(例如类似 的格式),该中间件会将其视为一个引用策略类的名称,进而动态导入该对象并调用它。 攻击者可通过构造恶意的 HTTP 响应头,注入可调用对象(如 ),从而导致正在处理该响应的爬虫进程被终止,引发拒绝服务(DoS)攻击。 该问题已在 Scrapy 2.14.2 版本中修复。

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105782

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
Source: CVE Program / CVE List V5
Vulnerability Description
Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler processing the response. This issue is fixed in version 2.14.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用外部可控制的输入来选择类或代码(不安全的反射)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
scrapy scrapy >= 1.4.0, < 2.14.2 -

II. Public POCs for CVE-2026-105782

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105782

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-105782 (2)

Vendor Advisories for CVE-2026-105782 (1)

Vendor Pages for CVE-2026-105782 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105782

No comments yet


Leave a comment