Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-71428— unstructured: Server-Side Request Forgery in the URL-based partitioning

Quick assessment

Affected
Unstructured-IO unstructured
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

unstructured 库为图像的摄取和预提供开源组件,支持处理图像和文本文档,例如 PDF、HTML、Word 文档等。从版本 0.4.7 到 0.24.0 之间, 、 和 函数中的 参数在 、 和 中被获取时,未进行主机名验证。攻击者若控制该 URL,可利用服务器端摄取服务访问环回地址、内部 HTTP 服务或云元数据端点,通过直接请求、重定向或 DNS 重绑定等方式实现攻击。响应内容会被作为 Element 文本返回,从而导致内部响应信息泄露,此外,还可能触发具有副作用的 GET 请求。该问题已在 0.24.

CVSS 9.3 · Critical EPSS 0.25% · P17

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unstructured-IO unstructured >= 0.4.7, < 0.24.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71428

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
unstructured: Server-Side Request Forgery in the URL-based partitioning
Source: CVE Program / CVE List V5
Vulnerability Description
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host validation in unstructured/partition/auto.py, unstructured/partition/html/partition.py, and unstructured/partition/md.py. An attacker who controls that URL can make a server-side ingestion service request loopback addresses, internal HTTP services, or cloud metadata endpoints through direct targets, redirects, or DNS rebinding. The response body is returned as Element text, allowing internal response disclosure, and side-effecting GET endpoints may also be triggered. This issue is fixed in version 0.24.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unstructured-IO unstructured >= 0.4.7, < 0.24.0 -

II. Public POCs for CVE-2026-71428

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71428

登录查看更多情报信息。

Patches & Fixes for CVE-2026-71428 (2)

Vendor Advisories for CVE-2026-71428 (1)

Vendor Pages for CVE-2026-71428 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-71428

No comments yet


Leave a comment