
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-105782 is an unsafe reflection vulnerability in Scrapy's RefererMiddleware that allows a malicious website to cause denial of service by terminating a crawler process. Affecting Scrapy versions 1.4.0 through 2.14.1, the flaw was published on October 6, 2026, and fixed in version 2.14.2. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat).
The root cause is CWE-470 (Use of Externally-Controlled Input to Select Classes or Code — 'Unsafe Reflection'). In scrapy/spidermiddlewares/referer.py, the _load_policy_class() function passed the Referrer-Policy response header value directly to load_object(), which interprets dot-separated strings as Python import paths and imports and calls the referenced object. A malicious server could set Referrer-Policy: sys.exit (or any other callable available in the Python environment), causing Scrapy to import and invoke it when processing the response. No authentication, privileges, or user interaction are required — the crawler simply needs to fetch a page from the attacker-controlled server (GitHub Advisory, GitHub Commit).
Successful exploitation causes a denial of service by abruptly terminating the Scrapy crawler process. Depending on the callable supplied (e.g., sys.exit, os.abort), the impact ranges from a clean process exit to a crash, disrupting any ongoing crawl jobs and potentially causing data loss for in-progress scraping tasks. Confidentiality and integrity are not directly impacted, but availability of the crawler is fully compromised for the duration of the attack (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires no privileges or user interaction and is network-accessible, making it straightforward to trigger against any crawler that visits an attacker-controlled website. It has not been added to the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been reported.
Referrer-Policy header, e.g., Referrer-Policy: sys.exit.RefererMiddleware enabled, which is the default) fetches a page from the malicious server — either by submitting the URL to a crawl queue, getting it linked from a legitimate site, or targeting a spider that crawls user-supplied URLs.RefererMiddleware._load_policy_class() receives the header value sys.exit, passes it to load_object(), which imports sys and retrieves the exit attribute.sys.exit()), immediately terminating the crawler process and causing a denial of service (GitHub Advisory, GitHub Commit).RuntimeWarning matching Could not load referrer policy '<value>' (import paths from the response Referrer-Policy header are not allowed) when running the patched version; unexpected abrupt process termination with no traceback in crawler logs on vulnerable versions.Referrer-Policy header value that resembles a Python import path (e.g., sys.exit, os.abort, or any dotted identifier string) rather than a standard policy name such as no-referrer or strict-origin-when-cross-origin.sys.exit()) or abnormally without a Python exception traceback, particularly shortly after fetching a specific URL.Upgrade Scrapy to version 2.14.2 or later, which restricts Referrer-Policy header values to known policy names and explicitly blocks import path resolution from response headers (GitHub Release). If immediate upgrade is not possible, the following workarounds are available: (1) set REFERER_ENABLED = False to disable the middleware entirely; (2) set the referrer_policy meta key on all requests (e.g., meta={"referrer_policy": "scrapy.spidermiddlewares.referer.DefaultReferrerPolicy"}) to prevent evaluation of response headers; or (3) replace the built-in middleware with a patched custom implementation (GitHub Advisory).
The vulnerability was reported by researcher Tomer-PL and the fix was developed and published by AdrianAtZyte of Zyte, the primary maintainer of Scrapy (GitHub Advisory). Red Hat tracked the issue via Bugzilla and assigned it high severity (Red Hat Bugzilla). No significant broader media coverage or notable community debate has been observed beyond standard vulnerability disclosure channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."