#VU118560 Resource exhaustion in scrapy - CVE-2025-6176
Published: November 17, 2025
scrapy
scrapy.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in its brotli decompression implementation. A remote attacker can trigger resource exhaustion and crash clients with less than 80GB of available memory.