CVE-2026-105782
Received Received - Intake

RefererMiddleware Remote Code Execution in Scrapy

Vulnerability report for CVE-2026-105782, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler processing the response. This issue is fixed in version 2.14.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
scrapy scrapy >= 1.4.0, < 2.14.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Scrapy versions 1.4.0 to 2.14.1. It involves the RefererMiddleware incorrectly treating Referrer-Policy header values that look like Python import paths as callable objects. A malicious site can exploit this by setting the header to something like 'sys.exit', causing the crawler to execute arbitrary code and terminate.

Detection Guidance

Check Scrapy version with pip show scrapy. If version is between 1.4.0 and 2.14.1, the system is vulnerable. Inspect HTTP responses for Referrer-Policy headers containing Python import paths like sys.exit. Monitor for unexpected process terminations during web scraping.

Impact Analysis

An attacker could cause a denial of service by terminating the crawler process. This could disrupt web scraping operations, lead to data loss, or allow arbitrary code execution on systems running vulnerable Scrapy versions.

Compliance Impact

This vulnerability primarily impacts availability by allowing denial of service through arbitrary code execution. It does not directly affect GDPR or HIPAA compliance as it does not involve unauthorized data access or processing violations. However, if exploited in a web scraping context, it could lead to disruptions in data collection processes that might indirectly impact compliance monitoring.

Mitigation Strategies

Upgrade Scrapy to version 2.14.2 or later using pip install --upgrade scrapy. Alternatively, disable RefererMiddleware in settings.py by setting REFERER_ENABLED to False. As a temporary measure, manually set Referer headers or configure referrer_policy in request metadata.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105782. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart