Resource exhaustion in scrapy - CVE-2025-6176

 

Resource exhaustion in scrapy - CVE-2025-6176

Published: November 17, 2025


Vulnerability identifier: #VU118560
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-6176
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in its brotli decompression implementation. A remote attacker can trigger resource exhaustion and crash clients with less than 80GB of available memory.


Affected software

scrapy
Netezza Appliance
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
brotli (Red Hat package)
python3-brotli
brotli-devel
brotli
python2-brotli
brotli-help
brotli-debugsource
brotli-debuginfo
python-scrapy
Red Hat OpenShift Container Platform
IBM CICS TX Standard
Juniper Junos Space

How to mitigate CVE-2025-6176

Install updates from vendor's website.

scrapy - update to 2.13.3
Netezza Appliance - update to 1.0.1.0 fp278500
brotli (Red Hat package) - addressed in versions 1.0.6-1.el8_2.1, 1.0.6-4.el8_4, 1.0.6-4.el8_6, 1.0.6-4.el8_8, 1.0.6-4.el8_10, 1.0.9-6.el9_0.1, 1.0.9-6.el9_4.1, 1.0.9-9.el9_7, 1.1.0-6.el10_0.1, 1.1.0-7.el10_1
python3-brotli - update to 1.0.6-4
brotli-devel - update to 1.0.6-4
brotli - update to 1.0.6-4
python2-brotli - update to 1.0.7-5
python3-brotli - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli-help - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli-debugsource - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli-debuginfo - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
brotli-devel - addressed in versions 1.0.7-5, 1.0.9-4, 1.1.0-2
python-scrapy - addressed in versions 2.13.4-1.fc43, 2.14.2-1.fc44
Red Hat OpenShift Container Platform - addressed in versions 4.12.86, 4.13.64, 4.14.62, 4.15.62, 4.16.58, 4.17.50, 4.18.34, 4.19.25
IBM CICS TX Standard - update to 11.1.0.0 ifix41
Juniper Junos Space - update to 26.1R1 Patch V1

External References

Related Security Bulletins