CVE-2026-84366 | Scrapy up to 2.16.x S3DownloadHandler s3.py is_secure missing encryption
A vulnerability, which was classified as problematic, was found in Scrapy up to 2.16.x. The impacted element is an unknown function of the file scrapy/core/downloader/handlers/s3.py of the component S3DownloadHandler. Such manipulation of the argument is_secure leads to missing encryption of sensitive data.
This vulnerability is referenced as CVE-2026-84366. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More