CVE-2026-71428Critical· 9.3▾ MidnightThe unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructured/partition/auto.py, unstructured/partition/html/partition.py, and unstructured/partition/md.py. An attacker who controls that URL can make a server-side ingestion service request loopback addresses, internal HTTP services, or cloud metadata endpoints through direct targets, redirects, or DNS rebinding. The response body is returned as Element text, allowing internal response disclosure, and side-effecting GET endpoints may also be triggered. This issue is fixed in version 0.24.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
unstructured >= 0.4.7, < 0.24.0Patched in:
unstructured 0.24.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-64712Critical· 9.8Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
CVE-2024-46455Mediumunstructured XML External Entity (XXE)
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-84282Medium· 6.5A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12
CVE-2026-86256Medium· 5.4wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)
CVE-2026-54770Medium· 6.1WebOb provides objects for HTTP requests and responses