Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cwxj-rr6w-m6w7 | Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware |
Tue, 06 Oct 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scrapy
Scrapy scrapy |
|
| Vendors & Products |
Scrapy
Scrapy scrapy |
Mon, 05 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler processing the response. This issue is fixed in version 2.14.2. | |
| Title | Scrapy: Arbitrary Module Import via Referrer-Policy Header in RefererMiddleware | |
| Weaknesses | CWE-470 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T23:08:55.749Z
Reserved: 2026-10-05T20:37:19.362Z
Link: CVE-2026-105782
No data.
Status : Received
Published: 2026-10-06T00:16:33.613
Modified: 2026-10-06T00:16:33.613
Link: CVE-2026-105782
No data.
OpenCVE Enrichment
Updated: 2026-10-06T00:30:18Z
-
CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Github GHSA