CVE-2024-1892

NameCVE-2024-1892
DescriptionParts of the Scrapy API were found to be vulnerable to a ReDoS attack. Handling a malicious response could cause extreme CPU and memory usage during the parsing of its content, due to the use of vulnerable regular expressions for that parsing.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1065111

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-scrapy (PTS)buster1.5.1-1+deb10u1vulnerable
bullseye2.4.1-2+deb11u1vulnerable
bookworm2.8.0-2vulnerable
sid, trixie2.11.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-scrapysource(unstable)2.11.1-11065111

Notes

[bookworm] - python-scrapy <no-dsa> (Minor issue)
[bullseye] - python-scrapy <no-dsa> (Minor issue)
[buster] - python-scrapy <no-dsa> (Minor issue)
https://huntr.com/bounties/271f94f2-1e05-4616-ac43-41752389e26b/
https://github.com/scrapy/scrapy/commit/479619b340f197a8f24c5db45bc068fb8755f2c5 (2.11.1)

Search for package or bug name: Reporting problems