LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-71428

Published
CVSS9.3
Severitycritical
WeaknessCWE-601
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Description

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructured/partition/auto.py, unstructured/partition/html/partition.py, and unstructured/partition/md.py. An attacker who controls that URL can make a server-side ingestion service request loopback addresses, internal HTTP services, or cloud metadata endpoints through direct targets, redirects, or DNS rebinding. The response body is returned as Element text, allowing internal response disclosure, and side

References

← Back to the CVE Tracker

Our coverage of CVE-2026-71428

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-71428.