Vulnerability DatabaseCVE-2026-105782

CVE-2026-105782: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-105782 is an unsafe reflection vulnerability in Scrapy's RefererMiddleware that allows a malicious website to cause denial of service by terminating a crawler process. Affecting Scrapy versions 1.4.0 through 2.14.1, the flaw was published on October 6, 2026, and fixed in version 2.14.2. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat).

Technical details

The root cause is CWE-470 (Use of Externally-Controlled Input to Select Classes or Code — 'Unsafe Reflection'). In scrapy/spidermiddlewares/referer.py, the _load_policy_class() function passed the Referrer-Policy response header value directly to load_object(), which interprets dot-separated strings as Python import paths and imports and calls the referenced object. A malicious server could set Referrer-Policy: sys.exit (or any other callable available in the Python environment), causing Scrapy to import and invoke it when processing the response. No authentication, privileges, or user interaction are required — the crawler simply needs to fetch a page from the attacker-controlled server (GitHub Advisory, GitHub Commit).

Impact

Successful exploitation causes a denial of service by abruptly terminating the Scrapy crawler process. Depending on the callable supplied (e.g., sys.exit, os.abort), the impact ranges from a clean process exit to a crash, disrupting any ongoing crawl jobs and potentially causing data loss for in-progress scraping tasks. Confidentiality and integrity are not directly impacted, but availability of the crawler is fully compromised for the duration of the attack (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires no privileges or user interaction and is network-accessible, making it straightforward to trigger against any crawler that visits an attacker-controlled website. It has not been added to the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been reported.

Exploitation steps

  1. Set up a malicious web server: Host a website on an attacker-controlled server that returns an HTTP response with a crafted Referrer-Policy header, e.g., Referrer-Policy: sys.exit.
  2. Lure or wait for the crawler: Ensure the target Scrapy crawler (running versions 1.4.0–2.14.1 with RefererMiddleware enabled, which is the default) fetches a page from the malicious server — either by submitting the URL to a crawl queue, getting it linked from a legitimate site, or targeting a spider that crawls user-supplied URLs.
  3. Trigger unsafe reflection: When Scrapy processes the HTTP response, RefererMiddleware._load_policy_class() receives the header value sys.exit, passes it to load_object(), which imports sys and retrieves the exit attribute.
  4. Execute the callable: Scrapy calls the resolved object (e.g., sys.exit()), immediately terminating the crawler process and causing a denial of service (GitHub Advisory, GitHub Commit).

Indicators of compromise

  • Logs: Scrapy log entries showing a RuntimeWarning matching Could not load referrer policy '<value>' (import paths from the response Referrer-Policy header are not allowed) when running the patched version; unexpected abrupt process termination with no traceback in crawler logs on vulnerable versions.
  • Network: HTTP responses from external hosts containing a Referrer-Policy header value that resembles a Python import path (e.g., sys.exit, os.abort, or any dotted identifier string) rather than a standard policy name such as no-referrer or strict-origin-when-cross-origin.
  • Process: Scrapy worker process exiting unexpectedly with exit code 0 (from sys.exit()) or abnormally without a Python exception traceback, particularly shortly after fetching a specific URL.

Mitigation and workarounds

Upgrade Scrapy to version 2.14.2 or later, which restricts Referrer-Policy header values to known policy names and explicitly blocks import path resolution from response headers (GitHub Release). If immediate upgrade is not possible, the following workarounds are available: (1) set REFERER_ENABLED = False to disable the middleware entirely; (2) set the referrer_policy meta key on all requests (e.g., meta={"referrer_policy": "scrapy.spidermiddlewares.referer.DefaultReferrerPolicy"}) to prevent evaluation of response headers; or (3) replace the built-in middleware with a patched custom implementation (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher Tomer-PL and the fix was developed and published by AdrianAtZyte of Zyte, the primary maintainer of Scrapy (GitHub Advisory). Red Hat tracked the issue via Bugzilla and assigned it high severity (Red Hat Bugzilla). No significant broader media coverage or notable community debate has been observed beyond standard vulnerability disclosure channels.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management