Package compatibility
Scrapy
Python requirements from PyPI (requires_python / classifiers) for the Scrapy package. This is not a lifecycle software page.
Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.
Version lines
Each line reflects a declared requires_python tip. Requirement changes across tips appear as separate lines when present.
Scrapy 2.13
tip 2.13.4Python >=3.9,<3.14
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Scrapy 2.14
tip 2.14.2Python >=3.10,<3.14
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Scrapy 2.15
tip 2.15.2Python >=3.10,<3.14
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Scrapy 2.16
tip 2.16.0Python >=3.10,<3.15
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Scrapy 2.17
tip 2.17.0Python >=3.10,<3.15
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Scrapy 2.18
tip 2.18.0Python >=3.10,<3.15
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2025-6176PYSEC-2026-1906
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
- Affected:
- <2.13.4
- Fixed in:
- 2.13.4
- Source:
- OSV source · Advisory
- CVE-2024-3572PYSEC-2026-1907
Scrapy decompression bomb vulnerability
- Affected:
- >=2.0.0,<2.11.1
- Fixed in:
- 2.11.1
- Source:
- OSV source · Advisory
- CVE-2024-3574PYSEC-2026-1908
Scrapy authorization header leakage on cross-domain redirect
- Affected:
- >=2,<2.11.1
- Fixed in:
- 2.11.1
- Source:
- OSV source · Advisory
- GHSA-cwxj-rr6w-m6w7
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
- Affected:
- >=1.4.0,<2.14.2
- Fixed in:
- 2.14.2
- Source:
- OSV source
- CVE-2025-6176GHSA-2qfp-q593-8484
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
- Affected:
- <2.13.4
- Fixed in:
- 2.13.4
- Source:
- OSV source · Advisory
- CVE-2024-1968PYSEC-2024-258
- Affected:
- >=2.0.0,<2.11.2; <1d0502f25bbe55a22899af915623fda1aaeb9dd8
- Fixed in:
- 2.11.2, 1d0502f25bbe55a22899af915623fda1aaeb9dd8
- Source:
- OSV source · Advisory
- GHSA-23j4-mw76-5v7h
Scrapy allows redirect following in protocols other than HTTP
- Affected:
- <2.11.2
- Fixed in:
- 2.11.2
- Source:
- OSV source
- GHSA-jm3v-qxmh-hxwv
Scrapy's redirects ignoring scheme-specific proxy settings
- Affected:
- <2.11.2
- Fixed in:
- 2.11.2
- Source:
- OSV source
- CVE-2024-1968GHSA-4qqq-9vqf-3h3f
Scrapy leaks the authorization header on same-domain but cross-origin redirects
- Affected:
- <2.11.2
- Fixed in:
- 2.11.2
- Source:
- OSV source
- CVE-2024-1892PYSEC-2024-162
- Affected:
- <2.11.1; <479619b340f197a8f24c5db45bc068fb8755f2c5
- Fixed in:
- 2.11.1, 479619b340f197a8f24c5db45bc068fb8755f2c5
- Source:
- OSV source · Advisory
- CVE-2024-3572GHSA-7j7m-v7m3-jqm7
Scrapy decompression bomb vulnerability
- Affected:
- <1.8.4; >=2.0.0,<2.11.1
- Fixed in:
- 1.8.4, 2.11.1
- Source:
- OSV source · Advisory
- CVE-2024-3574GHSA-cw9j-q3vf-hrrv
Scrapy authorization header leakage on cross-domain redirect
- Affected:
- <1.8.4; >=2,<2.11.1
- Fixed in:
- 1.8.4, 2.11.1
- Source:
- OSV source · Advisory
