{"api_version":"v1","generated_at":"2026-10-08T10:40:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-scrapy-scrapy-d3443eaf4c52","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/scrapy","name":"scrapy","next_cursor":null,"observations":[{"affected":"scrapy: >= 1.4.0, < 2.14.2","affected_versions_present":true,"cve_id":"CVE-2026-105782","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105782","fixed":"2.14.2.","last_modified":"2026-10-06T13:44:10.445Z","patch_url":"https://github.com/scrapy/scrapy/security/advisories/GHSA-cwxj-rr6w-m6w7","primary_source":"","published":"2026-10-05T23:08:55.749Z"},{"affected":"< 2.17.0","affected_versions_present":true,"cve_id":"CVE-2026-84366","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84366","fixed":"2.17.0.","last_modified":"2026-09-02T16:02:19.564Z","patch_url":"https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx","primary_source":"","published":"2026-09-01T20:29:23.143Z"},{"affected":"< 1.8.1; >= 2.0.0, < 2.5.1","affected_versions_present":true,"cve_id":"CVE-2021-41125","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41125","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T02:59:31.432Z","patch_url":"https://github.com/scrapy/scrapy/commit/b01d69a1bf48060daec8f751368622352d8b85a6","primary_source":"","published":"2021-10-06T17:15:13.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"scrapy"}}
