Resource exhaustion in scrapy - CVE-2025-6176
Published: November 17, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in its brotli decompression implementation. A remote attacker can trigger resource exhaustion and crash clients with less than 80GB of available memory.
Affected software
Netezza Appliance
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
brotli (Red Hat package)
python3-brotli
brotli-devel
brotli
python2-brotli
brotli-help
brotli-debugsource
brotli-debuginfo
python-scrapy
Red Hat OpenShift Container Platform
IBM CICS TX Standard
Juniper Junos Space
How to mitigate CVE-2025-6176
Netezza Appliance - update to 1.0.1.0 fp278500
brotli (Red Hat package) - addressed in versions 1.0.6-1.el8_2.1, 1.0.6-4.el8_4, 1.0.6-4.el8_6, 1.0.6-4.el8_8, 1.0.6-4.el8_10, 1.0.9-6.el9_0.1, 1.0.9-6.el9_4.1, 1.0.9-9.el9_7, 1.1.0-6.el10_0.1, 1.1.0-7.el10_1
python3-brotli - update to 1.0.6-4
brotli-devel - update to 1.0.6-4
brotli - update to 1.0.6-4
python2-brotli - update to 1.0.7-5
python3-brotli - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli-help - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli-debugsource - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli-debuginfo - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli-devel - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
python-scrapy - addressed in versions 2.13.4-1.fc43, 2.14.2-1.fc44
Red Hat OpenShift Container Platform - addressed in versions 4.12.86, 4.13.64, 4.14.62, 4.15.62, 4.16.58, 4.17.50, 4.18.34, 4.19.25
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Juniper Junos Space - update to 26.1R1 Patch V1
External References
Related Security Bulletins
- Resource exhaustion in Scrapy
- openEuler 24.03 LTS SP1 update for brotli
- openEuler 20.03 LTS SP4 update for brotli
- openEuler 24.03 LTS SP2 update for brotli
- openEuler 24.03 LTS update for brotli
- openEuler 22.03 LTS SP4 update for brotli
- openEuler 22.03 LTS SP3 update for brotli
- Red Hat Enterprise Linux 10 update for brotli
- Red Hat Enterprise Linux 10 update for brotli
- Red Hat Enterprise Linux 9 update for brotli
- Red Hat Enterprise Linux 9 update for brotli
- Red Hat Enterprise Linux 9 update for brotli
- Red Hat Enterprise Linux 8 update for brotli
- Red Hat Enterprise Linux 8 update for brotli
- Red Hat Enterprise Linux 8 update for brotli
- Red Hat Enterprise Linux 8 update for brotli
- Red Hat Enterprise Linux 8 update for brotli
- Resource exhaustion in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Anolis OS update for brotli
- Resource exhaustion in Red Hat OpenShift Container Platform 4.17
- Resource exhaustion in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM CICS TX Standard
- IBM Netezza Appliance update for Scrapy
- Fedora 44 update for python-scrapy
- Fedora 43 update for python-scrapy
- Multiple vulnerabilities in Junos Space