unstructured has 3 CVEs on record between 2024 and 2026. 1 was published in the last 90 days. The median CVSS is 9.6 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.6
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
3
Total CVEs
2
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2025-64712Critical· 9.8Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write54CVE-2026-71428Critical· 9.3The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more51CVE-2024-46455Mediumunstructured XML External Entity (XXE)28
unstructured vulnerabilities
CVEs affecting unstructured, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-71428Critical· 9.3The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…
▾ Midnightunstructured · unstructuredEPSS 0.25%via NVD
CVE-2025-64712Critical· 9.8Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
▾ Midnightunstructured · unstructuredEPSS 0.63%via OSV
CVE-2024-46455Mediumunstructured XML External Entity (XXE)
unstructured XML External Entity (XXE)
▾ Sunlitunstructured · unstructuredEPSS 0.57%via OSV