unstructured vulnerabilities
CVEs whose affected-version data names the unstructured package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-71428Critical· 9.3The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…
▾ Midnightunstructured · unstructuredEPSS 0.25%via NVD
CVE-2025-64712Critical· 9.8Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
▾ Midnightunstructured · unstructuredEPSS 0.63%via OSV
CVE-2024-46455Mediumunstructured XML External Entity (XXE)
unstructured XML External Entity (XXE)
▾ Sunlitunstructured · unstructuredEPSS 0.57%via OSV