Back to Database
Status published
High
CVE-2022-0577
Exposure of Sensitive Information to an Unauthorized Actor in scrapy/scrapy
Vulnerability Description
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-0577
Credits & Attribution
No credits recorded in the NVD database.
References
More from scrapy
View All →CVE-2025-6176
Brotli decompression bomb DoS in scrapy/scrapy
High
7.5
CVE-2024-3574
Authorization Header Leak During Cross-Domain Redirect in scrapy/scrapy
High
7.5
CVE-2024-3572
XML External Entity (XXE) Vulnerability in scrapy/scrapy
High
7.5
CVE-2024-1968
Authorization Header Leakage in scrapy/scrapy on Scheme Change Redirects
High
7.5
CVE-2024-1892
ReDoS Vulnerability in scrapy/scrapy's XMLFeedSpider
High
7.5
Affected Vendor
scrapy
View all reports →Affected Software
scrapy/scrapy
Vulnerable Versions:
unspecified
Timeline
Official Publish:
March 2nd, 2022
Last Modified:
August 2nd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H