CVE-2026-84366
Plaintext S3 requests expose credentials and data; MITM can tamper responses.
- CVSS 7.4
- 319
- Information Leakage
- Remote
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta["is_secure"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0.
- CWE
- 319
- CVSS base score
- 7.4
- Published
- 2026-09-01
- OWASP
- A02 Cryptographic Failures
- Orthogonal defect classification
- Interface
- Code defect classification
- Missing Check
- Category
- Information Leakage
- Subcategory
- Information Disclosure
- Accessibility scope
- Remote
- Impact
- Information Disclosure
- Affected component
- Scrapy
- Fixed by upgrading
- Yes
Solution
Upgrade Scrapy to version 2.17.0 or newer.
Vulnerable code sample
import urllib.parse
import requests
class S3DownloadHandler:
def __init__(self, aws_access_key, aws_secret_key):
self.aws_access_key = aws_access_key
self.aws_secret_key = aws_secret_key
def download(self, request):
# VULNERABLE: sends S3 request over plaintext HTTP
parsed = urllib.parse.urlparse(request.url)
bucket, key = parsed.netloc, parsed.path.lstrip('/')
endpoint = f"http://{bucket}.s3.amazonaws.com/{key}"
resp = requests.get(endpoint, auth=(self.aws_access_key, self.aws_secret_key))
return resp.contentPatched code sample
import urllib.parse
import requests
import botocore.auth
import botocore.awsrequest
import botocore.credentials
class S3DownloadHandler:
def __init__(self, aws_access_key, aws_secret_key):
self.creds = botocore.credentials.Credentials(aws_access_key, aws_secret_key)
def download(self, request):
# FIX: forces HTTPS and signs the request before sending
parsed = urllib.parse.urlparse(request.url)
bucket, key = parsed.netloc, parsed.path.lstrip('/')
endpoint = f"https://{bucket}.s3.amazonaws.com/{key}"
aws_req = botocore.awsrequest.AWSRequest(method="GET", url=endpoint)
signer = botocore.auth.SigV4Auth(self.creds, "s3", "us-east-1")
signer.add_auth(aws_req)
headers = dict(aws_req.headers)
resp = requests.get(endpoint, headers=headers)
return resp.contentCite this entry
@misc{vaitp:cve202684366,
title = {{Plaintext S3 requests expose credentials and data; MITM can tamper responses.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-84366},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-84366/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
