A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient regular expression complexity used in the parsing process, an attacker can cause a denial-of-service (DoS) condition. This vulnerability allows for the system to hang and consume significant resources, potentially rendering services that utilize Scrapy for XML processing unresponsive.
History

Fri, 10 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Scrapy
Scrapy scrapy
CPEs cpe:2.3:a:scrapy:scrapy:*:*:*:*:*:*:*:*
Vendors & Products Scrapy
Scrapy scrapy
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2024-08-11T14:28:49.917Z

Reserved: 2024-02-26T15:14:37.251Z

Link: CVE-2024-1892

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.557Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-28T00:15:53.897

Modified: 2025-01-10T14:49:33.690

Link: CVE-2024-1892

cve-icon Redhat

No data.