Vulnerability DatabaseGHSA-mfjm-vh54-3f96

GHSA-mfjm-vh54-3f96
Python vulnerability analysis and mitigation

Overview

A moderate severity vulnerability was identified in Scrapy (GHSA-mfjm-vh54-3f96), affecting versions <1.8.2 and >=2.0.0, <2.6.0. The vulnerability was published on March 1, 2022, and involves cookie-setting functionality that is not properly restricted based on the public suffix list (GitHub Advisory).

Technical details

The vulnerability allows responses from domain names with public domain name suffixes containing one or more periods (e.g., example.co.uk) to set cookies that are included in requests to any other domain sharing the same domain name suffix. This occurs because Scrapy does not properly validate cookie domains against the public suffix list (GitHub Advisory).

Impact

An attacker could exploit this vulnerability to inject cookies from a controlled domain into the victim's cookiejar, which could then be sent to other domains not controlled by the attacker. This could potentially lead to cookie injection attacks across domains sharing the same public suffix (GitHub Advisory).

Mitigation and workarounds

Users are advised to upgrade to Scrapy 2.6.0 or later, which implements proper cookie domain restrictions based on the public suffix list. For users on Scrapy 1.8 or lower versions who cannot upgrade to 2.6.0, upgrading to version 1.8.2 is recommended. Alternatively, users can either disable cookies altogether or limit target domains to those that don't include public domain suffixes with periods (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-5882-5rx9-xgxpCRITICAL10
  • PythonPython
  • crawl4ai
NoYesJan 16, 2026
GHSA-vx9w-5cx4-9796HIGH8.6
  • PythonPython
  • crawl4ai
NoYesJan 16, 2026
CVE-2026-23535HIGH8
  • PythonPython
  • wlc
NoYesJan 16, 2026
CVE-2026-23490HIGH7.5
  • PythonPython
  • pyasn1
NoYesJan 16, 2026
CVE-2026-23528MEDIUM5.3
  • PythonPython
  • distributed
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management