Package compatibility

Scrapy

Python requirements from PyPI (requires_python / classifiers) for the Scrapy package. This is not a lifecycle software page.

Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.

Version lines

Each line reflects a declared requires_python tip. Requirement changes across tips appear as separate lines when present.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2025-6176PYSEC-2026-1906

    Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

    Affected:
    <2.13.4
    Fixed in:
    2.13.4
    Source:
    OSV source · Advisory
  • CVE-2024-3572PYSEC-2026-1907

    Scrapy decompression bomb vulnerability

    Affected:
    >=2.0.0,<2.11.1
    Fixed in:
    2.11.1
    Source:
    OSV source · Advisory
  • CVE-2024-3574PYSEC-2026-1908

    Scrapy authorization header leakage on cross-domain redirect

    Affected:
    >=2,<2.11.1
    Fixed in:
    2.11.1
    Source:
    OSV source · Advisory
  • GHSA-cwxj-rr6w-m6w7

    Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware

    Affected:
    >=1.4.0,<2.14.2
    Fixed in:
    2.14.2
    Source:
    OSV source
  • CVE-2025-6176GHSA-2qfp-q593-8484

    Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

    Affected:
    <2.13.4
    Fixed in:
    2.13.4
    Source:
    OSV source · Advisory
  • CVE-2024-1968PYSEC-2024-258
    Affected:
    >=2.0.0,<2.11.2; <1d0502f25bbe55a22899af915623fda1aaeb9dd8
    Fixed in:
    2.11.2, 1d0502f25bbe55a22899af915623fda1aaeb9dd8
    Source:
    OSV source · Advisory
  • GHSA-23j4-mw76-5v7h

    Scrapy allows redirect following in protocols other than HTTP

    Affected:
    <2.11.2
    Fixed in:
    2.11.2
    Source:
    OSV source
  • GHSA-jm3v-qxmh-hxwv

    Scrapy's redirects ignoring scheme-specific proxy settings

    Affected:
    <2.11.2
    Fixed in:
    2.11.2
    Source:
    OSV source
  • CVE-2024-1968GHSA-4qqq-9vqf-3h3f

    Scrapy leaks the authorization header on same-domain but cross-origin redirects

    Affected:
    <2.11.2
    Fixed in:
    2.11.2
    Source:
    OSV source
  • CVE-2024-1892PYSEC-2024-162
    Affected:
    <2.11.1; <479619b340f197a8f24c5db45bc068fb8755f2c5
    Fixed in:
    2.11.1, 479619b340f197a8f24c5db45bc068fb8755f2c5
    Source:
    OSV source · Advisory
  • CVE-2024-3572GHSA-7j7m-v7m3-jqm7

    Scrapy decompression bomb vulnerability

    Affected:
    <1.8.4; >=2.0.0,<2.11.1
    Fixed in:
    1.8.4, 2.11.1
    Source:
    OSV source · Advisory
  • CVE-2024-3574GHSA-cw9j-q3vf-hrrv

    Scrapy authorization header leakage on cross-domain redirect

    Affected:
    <1.8.4; >=2,<2.11.1
    Fixed in:
    1.8.4, 2.11.1
    Source:
    OSV source · Advisory