PatchSiren

Unstructured-IO CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Unstructured-IO CVE published 2026-08-20

CVE-2026-71428

CVE-2026-71428 is a critical vulnerability in the unstructured library, which allows an attacker to make a server-side ingestion service request loopback addresses, internal HTTP services, or cloud metadata endpoints. This issue is fixed in version 0.24.0. The vulnerability exists in versions 0.4.7 to 0.24.0 of the unstructured library. An attacker can exploit this vulnerability by controlling the URL arg [truncated]