Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade brotli-develUpgrade brotliUpgrade libbrotliUpgrade python3-brotli | Feb 6, 2026 | Feb 5, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade brotli | Jan 15, 2026 | Jan 13, 2026 |
| Huawei Euleros 2_0_sp11 | — | Upgrade brotli | Mar 17, 2026 | Mar 17, 2026 |
| Huawei Euleros 2_0_sp12 | — | Upgrade brotli | Jan 15, 2026 | Jan 13, 2026 |
| Huawei Euleros 2_0_sp13 | — | Upgrade brotli | Feb 3, 2026 | Jan 30, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | May 12, 2026 |
| Oracle_linux | — | Upgrade libbrotliUpgrade brotli-develUpgrade brotliUpgrade python3-brotli | Jan 21, 2026 | Oct 31, 2025 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Oct 31, 2025 |
| Redhat_linux | — | Upgrade brotli-debuginfoUpgrade brotli-debugsourceUpgrade python3-brotliUpgrade libbrotliUpgrade python3-brotli-debuginfoUpgrade libbrotli-debuginfoUpgrade brotli-develUpgrade brotli | Jan 6, 2026 | Oct 31, 2025 |
| Rocky_linux | — | Upgrade libbrotliUpgrade python3-brotliUpgrade brotli-debuginfoUpgrade brotli-develUpgrade python3-brotli-debuginfoUpgrade brotli-debugsourceUpgrade brotliUpgrade libbrotli-debuginfo | Jan 22, 2026 | Jan 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub