Scrapy's redirects ignoring scheme-specific proxy settings
Scrapy versions from 2.9.0 up to but not including 2.11.2 have a vulnerability where redirects do not properly switch proxy settings based on URL scheme changes (HTTP to HTTPS or vice versa). This causes the proxy configured for one scheme to be incorrectly used for the other, potentially leaking browsing information between proxies. The issue is fixed in Scrapy 2.11.2.
AI Analysis
Technical Summary
Scrapy's handling of system proxy settings is scheme-specific, meaning different proxies can be set for HTTP and HTTPS URLs. However, during HTTP redirects that change the URL scheme, Scrapy did not update the proxy accordingly. For example, an HTTP request using an HTTP proxy redirected to an HTTPS URL would still use the HTTP proxy instead of switching to the HTTPS proxy. This flaw could expose URLs visited via one proxy to another proxy provider, undermining security configurations that rely on scheme-specific proxies. The vulnerability affects Scrapy versions >=2.9.0 and <2.11.2 and is resolved by upgrading to version 2.11.2.
Potential Impact
The vulnerability can lead to unintended proxy usage during redirects, potentially exposing URLs to proxy providers that should not have access to them. This compromises the confidentiality of browsing activity when different proxies are used for HTTP and HTTPS for security reasons. There is no indication of integrity or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade Scrapy to version 2.11.2 or later, where this issue is fixed. Alternatively, implement custom middleware replacements for RedirectMiddleware, MetaRefreshMiddleware, and HttpProxyMiddleware that incorporate the fix from Scrapy 2.11.2. Verify the custom solution correctly handles scheme-specific proxy switching during redirects.
Scrapy's redirects ignoring scheme-specific proxy settings
Description
Scrapy versions from 2.9.0 up to but not including 2.11.2 have a vulnerability where redirects do not properly switch proxy settings based on URL scheme changes (HTTP to HTTPS or vice versa). This causes the proxy configured for one scheme to be incorrectly used for the other, potentially leaking browsing information between proxies. The issue is fixed in Scrapy 2.11.2.
CVSS v3.1
Score 4.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Scrapy's handling of system proxy settings is scheme-specific, meaning different proxies can be set for HTTP and HTTPS URLs. However, during HTTP redirects that change the URL scheme, Scrapy did not update the proxy accordingly. For example, an HTTP request using an HTTP proxy redirected to an HTTPS URL would still use the HTTP proxy instead of switching to the HTTPS proxy. This flaw could expose URLs visited via one proxy to another proxy provider, undermining security configurations that rely on scheme-specific proxies. The vulnerability affects Scrapy versions >=2.9.0 and <2.11.2 and is resolved by upgrading to version 2.11.2.
Potential Impact
The vulnerability can lead to unintended proxy usage during redirects, potentially exposing URLs to proxy providers that should not have access to them. This compromises the confidentiality of browsing activity when different proxies are used for HTTP and HTTPS for security reasons. There is no indication of integrity or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade Scrapy to version 2.11.2 or later, where this issue is fixed. Alternatively, implement custom middleware replacements for RedirectMiddleware, MetaRefreshMiddleware, and HttpProxyMiddleware that incorporate the fix from Scrapy 2.11.2. Verify the custom solution correctly handles scheme-specific proxy switching during redirects.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-scrapy-GHSA-jm3v-qxmh-hxwv
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6aac8e5655bf5e2cf5491815
Added to database: 09/18/2026, 01:05:26 UTC
Last enriched: 09/18/2026, 01:50:02 UTC
Last updated: 09/18/2026, 02:07:39 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.