Inefficient regular expression complexity in scrapy - #VU127073
Published: February 14, 2024 / Updated: April 23, 2026
scrapy
scrapy.org
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in open_in_browser when processing a response without a base tag. A remote attacker can provide a specially crafted response to cause a denial of service.
This issue affects Scrapy 2.6.0 through 2.11.0.