Package compatibility
Scrapy 2.13
What Python versions does this Scrapy version support?
Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.
Declared Python requirement
- requires_python
- >=3.9,<3.14
- Tip version
- 2.13.4
- Source
- PyPI (requires_python / classifiers)
Python compatibility matrix
Evaluated against CompatHub Python VersionLines. Compatibility and lifecycle status are separate signals.
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Other Scrapy lines
Security
Advisories affecting Scrapy 2.13 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 5
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2025-6176PYSEC-2026-1906
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
- Affected:
- <2.13.4
- Fixed in:
- 2.13.4
- Source:
- OSV source · Advisory
- GHSA-cwxj-rr6w-m6w7
Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware
- Affected:
- >=1.4.0,<2.14.2
- Fixed in:
- 2.14.2
- Source:
- OSV source
- CVE-2025-6176GHSA-2qfp-q593-8484
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
- Affected:
- <2.13.4
- Fixed in:
- 2.13.4
- Source:
- OSV source · Advisory
- CVE-2017-14158GHSA-h7wm-ph43-c39p
Scrapy denial of service vulnerability
- Affected:
- >=0.7,<=2.15.2
- Source:
- OSV source · Advisory
- CVE-2017-14158PYSEC-2017-83
- Affected:
- >=0.7
- Source:
- OSV source · Advisory
