PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46497 apify CVE debrief

Crawlee, a web scraping and browser automation library, is vulnerable to SSRF via sitemap-derived URLs from version 1.0.0 to before version 1.7.0. This issue is patched in version 1.7.0.

Vendor
apify
Product
crawlee-python
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-10
Original CVE updated
2026-06-10
Advisory published
2026-06-10
Advisory updated
2026-06-10

Who should care

Users of Crawlee library versions between 1.0.0 and 1.7.0.

Technical summary

The Crawlee library is vulnerable to Server-Side Request Forgery (SSRF) via sitemap-derived URLs. This vulnerability exists from version 1.0.0 up to but not including version 1.7.0. The issue has been addressed with the release of version 1.7.0.

Defensive priority

LOW

Recommended defensive actions

  • Upgrade Crawlee library to version 1.7.0 or later.

Evidence notes

CVE-2026-46497 has a CVSS score of 2.3, indicating a low severity vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46497 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46497

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46497 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46497

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.