Inefficient regular expression complexity in scrapy - #VU127072
Published: February 14, 2024 / Updated: April 23, 2026
scrapy
scrapy.org
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in XMLFeedSpider default node iterator and scrapy.utils.iterators.xmliter when parsing malicious response content. A remote attacker can send a specially crafted response to cause a denial of service.
The issue can lead to extreme CPU and memory usage during content parsing.