Server-Side Vulnerability in Unstructured Library for Image and Document Processing
CVE-2026-71428
9.3CRITICAL
What is CVE-2026-71428?
The Unstructured library, an open-source tool designed for ingesting and pre-processing images and text documents like PDFs, HTML, and Word documents, has a vulnerability that affects versions 0.4.7 through 0.24.0. The issue arises from inadequate validation of the 'url' argument used in the partition functions, allowing attackers to initiate requests to server-side ingestion services that could reach internal HTTP services or cloud metadata endpoints. As a result, this could lead to the disclosure of internal response data and the unintended triggering of GET endpoints due to response handling. This vulnerability has been mitigated in version 0.24.0.
Affected Version(s)
unstructured >= 0.4.7, < 0.24.0
