CRITICAL
Unstructured-IO
CVE published 2026-08-20
CVE-2026-71428
CVE-2026-71428 is a critical vulnerability in the unstructured library, which allows an attacker to make a server-side ingestion service request loopback addresses, internal HTTP services, or cloud metadata endpoints. This issue is fixed in version 0.24.0. The vulnerability exists in versions 0.4.7 to 0.24.0 of the unstructured library. An attacker can exploit this vulnerability by controlling the URL arg [truncated]