{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/scrapy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:scrapy:scrapy:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-84366"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Scrapy (\u003c 2.17.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud","web-scraping"],"_cs_type":"advisory","_cs_vendors":["Scrapy"],"content_html":"\u003cp\u003eThe Scrapy web crawling framework contains a security vulnerability (CVE-2026-84366) in its \u003ccode\u003eS3DownloadHandler\u003c/code\u003e component. By default, when a user initiates a request to an \u003ccode\u003es3://\u003c/code\u003e URI, the handler constructs an HTTP URL (\u003ccode\u003ehttp://bucket.s3.amazonaws.com/key\u003c/code\u003e) unless the \u003ccode\u003erequest.meta[\u0026quot;is_secure\u0026quot;]\u003c/code\u003e flag is explicitly set to \u003ccode\u003eTrue\u003c/code\u003e. Because the request is signed with the user's AWS credentials before being dispatched, the authorization headers and security tokens are transmitted over plaintext HTTP. This behavior persists in all versions of Scrapy prior to 2.17.0.\u003c/p\u003e\n\u003cp\u003eThis issue is particularly critical for environments where Scrapy workers operate in untrusted network segments or where traffic is subject to interception. Attackers capable of observing or intercepting network traffic can capture valid AWS credentials or perform full Man-in-the-Middle (MITM) attacks to manipulate data being scraped, potentially leading to downstream data poisoning or influence over the crawl process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a network attacker to capture sensitive AWS authorization material, including long-lived IAM keys or temporary session tokens (via \u003ccode\u003eX-Amz-Security-Token\u003c/code\u003e). Additionally, the ability to perform MITM attacks against the plaintext stream enables the injection of malicious content into the scraped dataset, the corruption of HTTP caches, and the redirection of crawlers to attacker-controlled targets. This vulnerability affects any organization utilizing Scrapy to interact with S3-compatible storage using IAM-based authentication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Scrapy to version 2.17.0 or later immediately to resolve the default insecure connection behavior.\u003c/li\u003e\n\u003cli\u003eAudit existing Scrapy spiders for usage of \u003ccode\u003es3://\u003c/code\u003e URIs and explicitly set \u003ccode\u003erequest.meta[\u0026quot;is_secure\u0026quot;] = True\u003c/code\u003e for all S3 requests if an immediate upgrade is not feasible.\u003c/li\u003e\n\u003cli\u003eImplement network-level egress filtering and enforce TLS for all outgoing storage traffic to detect or prevent non-encrypted AWS API communications.\u003c/li\u003e\n\u003cli\u003eRotate any AWS IAM credentials that have been used by Scrapy instances operating in environments susceptible to network eavesdropping.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T00:03:28Z","date_published":"2026-09-03T00:03:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-scrapy-s3-plaintext/","summary":"The Scrapy S3DownloadHandler defaults to sending signed AWS S3 requests over plaintext HTTP, potentially exposing AWS authorization headers and security tokens to network-based attackers.","title":"Scrapy S3DownloadHandler Vulnerable to Credential Exposure via Plaintext HTTP","url":"https://feed.craftedsignal.io/briefs/2026-09-scrapy-s3-plaintext/"}],"language":"en","title":"CraftedSignal Threat Feed - Scrapy","version":"https://jsonfeed.org/version/1.1"}