S3 Download Handler Issue in Scrapy Framework Affecting AWS Credentials
CVE-2026-84366

7.4HIGH

Key Information:

Vendor

Scrapy

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84366?

The Scrapy framework's S3 Download Handler issue allows an unauthorized exposure of sensitive data due to requests being sent as plaintext HTTP. If users do not enable the secure request option, AWS credentials along with S3 bucket and key details can be intercepted by attackers. Not only can attackers read sensitive data, but they can also modify response bodies and headers, leading to scraped data poisoning or influencing future crawls through altered redirects. This vulnerability affects users making S3 requests containing AWS credentials and has been resolved in Scrapy version 2.17.0.

Affected Version(s)

scrapy < 2.17.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.