Cleartext transmission of sensitive information in scrapy - CVE-2026-84366

 

Cleartext transmission of sensitive information in scrapy - CVE-2026-84366

Published: July 7, 2026 / Updated: September 2, 2026


Vulnerability identifier: #VU137025
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84366
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and modify transmitted data.

The vulnerability exists due to cleartext transmission of sensitive information in the S3DownloadHandler when sending signed s3 requests over plaintext http by default. A remote attacker can observe or tamper with network traffic to disclose sensitive information and modify transmitted data.

Only requests made with AWS credentials are affected, and temporary credentials may expose the X-Amz-Security-Token.


Affected software

scrapy

How to mitigate CVE-2026-84366

Install security update from vendor's website.

scrapy - update to 2.17.0

External References

Related Security Bulletins