S3 Download Handler Issue in Scrapy Framework Affecting AWS Credentials
CVE-2026-84366
7.4HIGH
What is CVE-2026-84366?
The Scrapy framework's S3 Download Handler issue allows an unauthorized exposure of sensitive data due to requests being sent as plaintext HTTP. If users do not enable the secure request option, AWS credentials along with S3 bucket and key details can be intercepted by attackers. Not only can attackers read sensitive data, but they can also modify response bodies and headers, leading to scraped data poisoning or influencing future crawls through altered redirects. This vulnerability affects users making S3 requests containing AWS credentials and has been resolved in Scrapy version 2.17.0.
Affected Version(s)
scrapy < 2.17.0
