The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Scrapy
Scrapy scrapy |
|
CPEs | cpe:2.3:a:scrapy:scrapy:*:*:*:*:*:*:*:* | |
Vendors & Products |
Scrapy
Scrapy scrapy |

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T20:12:07.961Z
Reserved: 2024-04-10T09:54:09.923Z
Link: CVE-2024-3572

Updated: 2024-08-01T20:12:07.961Z

Status : Analyzed
Published: 2024-04-16T00:15:12.387
Modified: 2025-07-28T14:49:45.790
Link: CVE-2024-3572

No data.