Denial of Service Vulnerability in Scrapy Product by Scrapinghub
CVE-2025-6176
7.5HIGH
What is CVE-2025-6176?
Scrapy is susceptible to a denial of service attack stemming from a vulnerability in its brotli decompression implementation. This weakness in the protection mechanism allows attackers to exploit the brotli variant, potentially leading remote servers to crash clients that have less than 80GB of available memory. Since brotli compression achieves exceptionally high ratios, particularly with zero-filled data, the decompression process can result in significant memory usage, rendering the system vulnerable to service disruption.
Affected Version(s)
scrapy/scrapy <= unspecified
