<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:36:09.066170+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-scrapy-cve-2024-1892</id>
    <title>BREW-scrapy-CVE-2024-1892 — ReDoS Vulnerability in scrapy/scrapy's XMLFeedSpider</title>
    <updated>2026-10-05T15:36:09.068423+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: scrapy</p>
<p>A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient regular expression complexity used in the parsing process, an attacker can cause a denial-of-service (DoS) condition. This vulnerability allows for the system to hang and consume significant resources, potentially rendering services that utilize Scrapy for XML processing unresponsive.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-scrapy-cve-2024-1892"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-1892</id>
    <title>CVE-2024-1892 — ReDoS Vulnerability in scrapy/scrapy's XMLFeedSpider</title>
    <updated>2026-10-05T15:36:09.068471+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> scrapy/scrapy, scrapy</p>
<p>A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient regular expression complexity used in the parsing process, an attacker can cause a denial-of-service (DoS) condition. This vulnerability allows for the system to hang and consume significant resources, potentially rendering services that utilize Scrapy for XML processing unresponsive.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-1892"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cc65-xxvf-f7r9</id>
    <title>GHSA-cc65-xxvf-f7r9 — Scrapy vulnerable to ReDoS via XMLFeedSpider</title>
    <updated>2026-10-05T15:36:09.068503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: scrapy</p>
<p>### Impact</p>
<p>The following parts of the Scrapy API were found to be vulnerable to a [ReDoS attack](https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS):</p>
<p>- The [`XMLFeedSpider`](https://docs.scrapy.org/en/latest/topics/spiders.html#scrapy.spiders.XMLFeedSpider) class or any subclass that uses the default node iterator: `iternodes`, as well as direct uses of the `scrapy.utils.iterators.xmliter` function.</p>
<p>- **Scrapy 2.6.0 to 2.11.0**: The [`open_in_browser`](https://docs.scrapy.org/en/latest/topics/debug.html#scrapy.utils.response.open_in_browser) function for a response without a [base tag](https://www.w3schools.com/tags/tag_base.asp).</p>
<p>Handling a malicious response could cause extreme CPU and memory usage during the parsing of its content, due to the use of vulnerable regular expressions for that parsing.</p>
<p>### Patches</p>
<p>Upgrade to Scrapy 2.11.1.</p>
<p>If you are using Scrapy 1.8 or a lower version, and upgrading to Scrapy 2.11.1 is not an option, you may upgrade to Scrapy 1.8.4 instead.</p>
<p>### Workarounds</p>
<p>For `XMLFeedSpider`, switch the node iterator to ``xml`` or ``html``.</p>
<p>For `open_in_browser`, before using the function, either manually review the response content to discard a ReDos attack or manually define the base tag to avoid its automatic definition by `open_in_browser` later.</p>
<p>### Acknowledgements</p>
<p>This security issue was reported by @nicecatch2000  [through huntr.com](https://huntr.com/bounties/271f94f2-1e05-4616-ac43-41752389e26b/).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cc65-xxvf-f7r9"/>
  </entry>
</feed>
