PT-2026-79067 · Pypi · Unstructured

CVE-2026-71428

·

Published

2026-08-20

·

Updated

2026-09-10

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions unstructured versions 0.4.7 through 0.23.x
Description The library fails to validate the host when fetching the url argument in the partition(), partition html(), and partition md() functions. This allows an attacker to force the server-side ingestion service to make requests to loopback addresses, internal HTTP services, or cloud metadata endpoints via direct targets, redirects, or DNS rebinding. Consequently, the response body is returned as Element text, which can lead to the disclosure of internal responses or the triggering of side-effecting GET endpoints.
Recommendations Update to version 0.24.0.

Exploit

Fix

SSRF

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71428
GHSA-4MVJ-M6J5-PMF7
PYSEC-2026-3930

Affected Products

Unstructured