Denial of Service Vulnerability in Scrapy Product by Scrapinghub
CVE-2025-6176

7.5HIGH

Key Information:

Vendor

Scrapy

Vendor
CVE Published:
31 October 2025

What is CVE-2025-6176?

Scrapy is susceptible to a denial of service attack stemming from a vulnerability in its brotli decompression implementation. This weakness in the protection mechanism allows attackers to exploit the brotli variant, potentially leading remote servers to crash clients that have less than 80GB of available memory. Since brotli compression achieves exceptionally high ratios, particularly with zero-filled data, the decompression process can result in significant memory usage, rendering the system vulnerable to service disruption.

Affected Version(s)

scrapy/scrapy <= unspecified

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.