CVE-2026-71428: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in Unstructured-IO unstructured
CVE-2026-71428 is a critical open redirect vulnerability in the unstructured library versions from 0.4.7 up to but not including 0.24.0. The vulnerability occurs because the url argument in certain partitioning functions is fetched without validating the host, allowing an attacker to cause server-side requests to internal or cloud metadata endpoints. This can lead to disclosure of internal response data and potential triggering of side-effecting GET endpoints. The issue is fixed in version 0.24.0.
AI Analysis
Technical Summary
The unstructured library, used for ingesting and pre-processing various document types, contains an open redirect vulnerability (CWE-601) in versions 0.4.7 through 0.23.x. The url argument in partition, partition_html, and partition_md functions is fetched without host validation in multiple source files. An attacker controlling this URL can induce server-side requests to internal or cloud metadata services via direct targets, redirects, or DNS rebinding. The response body is returned as Element text, enabling internal data disclosure and potential side effects from GET requests. This vulnerability is addressed in version 0.24.0.
Potential Impact
An attacker can exploit this vulnerability to make the server-side ingestion service perform unauthorized requests to internal network resources, including loopback addresses and cloud metadata endpoints. This can lead to disclosure of sensitive internal information and may trigger side effects on internal HTTP services. The CVSS 3.1 score of 9.3 reflects a critical severity with high confidentiality impact and low integrity impact.
Mitigation Recommendations
A fix is available in unstructured version 0.24.0. Users should upgrade to version 0.24.0 or later to remediate this vulnerability. Until upgraded, avoid processing untrusted URLs with the affected partitioning functions or implement additional host validation controls externally.
CVE-2026-71428: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in Unstructured-IO unstructured
Description
CVE-2026-71428 is a critical open redirect vulnerability in the unstructured library versions from 0.4.7 up to but not including 0.24.0. The vulnerability occurs because the url argument in certain partitioning functions is fetched without validating the host, allowing an attacker to cause server-side requests to internal or cloud metadata endpoints. This can lead to disclosure of internal response data and potential triggering of side-effecting GET endpoints. The issue is fixed in version 0.24.0.
CVSS v3.1
Score 9.3critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The unstructured library, used for ingesting and pre-processing various document types, contains an open redirect vulnerability (CWE-601) in versions 0.4.7 through 0.23.x. The url argument in partition, partition_html, and partition_md functions is fetched without host validation in multiple source files. An attacker controlling this URL can induce server-side requests to internal or cloud metadata services via direct targets, redirects, or DNS rebinding. The response body is returned as Element text, enabling internal data disclosure and potential side effects from GET requests. This vulnerability is addressed in version 0.24.0.
Potential Impact
An attacker can exploit this vulnerability to make the server-side ingestion service perform unauthorized requests to internal network resources, including loopback addresses and cloud metadata endpoints. This can lead to disclosure of sensitive internal information and may trigger side effects on internal HTTP services. The CVSS 3.1 score of 9.3 reflects a critical severity with high confidentiality impact and low integrity impact.
Mitigation Recommendations
A fix is available in unstructured version 0.24.0. Users should upgrade to version 0.24.0 or later to remediate this vulnerability. Until upgraded, avoid processing untrusted URLs with the affected partitioning functions or implement additional host validation controls externally.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-06T16:28:51.182Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8730d9acd9273b49e1718f
Added to database: 08/20/2026, 16:52:41 UTC
Last enriched: 08/20/2026, 17:07:36 UTC
Last updated: 08/20/2026, 17:35:43 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.