In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:scrapy:scrapy:*:*:*:*:*:*:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T20:12:08.239Z
Reserved: 2024-04-10T09:54:50.274Z
Link: CVE-2024-3574

Updated: 2024-08-01T20:12:08.239Z

Status : Analyzed
Published: 2024-04-16T00:15:12.750
Modified: 2025-07-28T14:51:40.343
Link: CVE-2024-3574

No data.