Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-brotliUpgrade libbrotliUpgrade brotliUpgrade brotli-devel | Feb 6, 2026 | Feb 5, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade brotli | Jan 15, 2026 | Jan 13, 2026 |
| Huawei Euleros 2_0_sp11 | — | Upgrade brotli | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade brotli | Jan 15, 2026 | Jan 13, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade brotli | Feb 3, 2026 | Jan 30, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | May 12, 2026 |
| Oracle_linux | — | Upgrade python3-brotliUpgrade libbrotliUpgrade brotli-develUpgrade brotli | Jan 21, 2026 | Oct 31, 2025 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Oct 31, 2025 |
| Redhat_linux | — | Upgrade python3-brotliUpgrade brotli-debugsourceUpgrade brotli-debuginfoUpgrade brotli-develUpgrade libbrotli-debuginfoUpgrade libbrotliUpgrade brotliUpgrade python3-brotli-debuginfo | Jan 6, 2026 | Oct 31, 2025 |
| Rocky_linux | — | Upgrade brotli-develUpgrade brotli-debugsourceUpgrade libbrotli-debuginfoUpgrade python3-brotli-debuginfoUpgrade brotliUpgrade libbrotliUpgrade brotli-debuginfoUpgrade python3-brotli | Jan 22, 2026 | Jan 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub