Sploitus

CVE-2024-1892

No indexed exploits for CVE-2024-1892 yet

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By crafting malicious XML content that exploits inefficient regular expression complexity used in the parsing process, an attacker can cause a denial-of-service (DoS) condition. This vulnerability allows for the system to hang and consume significant resources, potentially rendering services that utilize Scrapy for XML processing unresponsive.

Affected products
Debian, Linuxmint, Scrapy, Ubuntu
Scrapy
< 2.11.1
Fix
Available
CVSS 3.0
7.5 HIGH
EPSS
0.6% (44th percentile)
Weakness
CWE-1333
NVD status
Analyzed
Published
2024-02-28
CVE-2024-1892 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-1892 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-1892 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.