Threat Advisory

Scrapy S3DownloadHandler Sends Signed S3 Requests Over Plaintext HTTP by Default

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-84366 is a HIGH severity CWE-319 Cleartext Transmission of Sensitive Information vulnerability in Scrapy's S3DownloadHandler that sends signed S3 requests over plaintext HTTP by default. This makes users making Scrapy s3:// requests with AWS credentials vulnerable to network attackers who can read bucket/key path, AWS Authorization header, X-Amz-Security-Token, S3 object contents, and S3 response headers. An active MITM attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes it, causing scraped data poisoning, poisoned exports, HTTP cache poisoning when cache is enabled, and influence over later crawl targets through forged redirects or attacker-controlled links. The vulnerability has a CVSS v3 score of 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) and affects versions prior to 2.17.0.

RECOMMENDATION:

We recommend you to update Scrapy to version 2.17.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-84366 is a HIGH severity CWE-319 Cleartext Transmission of Sensitive Information vulnerability in Scrapy's S3DownloadHandler that sends signed S3 requests over plaintext HTTP by default. This makes users making Scrapy s3:// requests with AWS credentials vulnerable to network attackers who can read bucket/key path, AWS Authorization header, X-Amz-Security-Token, S3 object contents, and S3 response headers. An active MITM attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes it, causing scraped data poisoning, poisoned exports, HTTP cache poisoning when cache is enabled, and influence over later crawl targets through forged redirects or attacker-controlled links. The vulnerability has a CVSS v3 score of 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N) and affects versions prior to 2.17.0.

RECOMMENDATION:

We recommend you to update Scrapy to version 2.17.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu