OSS Support Hub / Developer Tools

Python Developer Tools BSD-3-Clause Latest: 2.16.0

Scrapy

Fast high-level web crawling and scraping framework for Python

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

62.7K+673
GitHub Stars
📦
2.16.0
Latest Release · 1 months ago
🔄
38d
Avg. Release Cadence
🐛
611
Open Issues
📅
3 days ago
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Scrapy allows redirect following in protocols other than HTTP

Published: 2024-05-14 Fixed in: 2.11.2

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Published: 2025-10-31 Fixed in: 1.2.0

Scrapy leaks the authorization header on same-domain but cross-origin redirects

Published: 2024-05-14 Fixed in: 2.11.2

Scrapy decompression bomb vulnerability

Published: 2024-02-16 Fixed in: 2.11.1

Scrapy before 2.6.2 and 1.8.3 vulnerable to one proxy sending credentials to another

Published: 2022-07-29 Fixed in: 1.8.3

Scrapy vulnerable to ReDoS via XMLFeedSpider

Published: 2024-02-15 Fixed in: 2.11.1

Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy

Published: 2022-03-01 Fixed in: 1.8.2

Scrapy authorization header leakage on cross-domain redirect

Published: 2024-02-15 Fixed in: 2.11.1

Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware

Published: 2026-03-13 Fixed in: 2.14.2

Scrapy denial of service vulnerability

Published: 2022-05-17 No fix available

Alternatives to Scrapy

Other Developer Tools projects in the Python ecosystem worth evaluating.

Support Options for Scrapy

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Scrapy — without relying on volunteer maintainers.