CVE-2026-71428: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in Unstructured-IO unstructured
Description
CVE-2026-71428 is an open redirect vulnerability in the unstructured library versions from 0.4.7 up to but not including 0.24.0. The library's functions partition, partition_html, and partition_md fetch URLs without validating the host, allowing attackers controlling the URL to induce server-side requests to internal or cloud metadata endpoints. This can lead to disclosure of internal responses and potentially trigger side-effecting GET endpoints. The vulnerability is fixed in version 0.24.0.
CVSS v3.1
Score 9.3critical
Affected software
Unstructured-IO
unstructured
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The unstructured library, used for ingesting and preprocessing various document types, contains an open redirect vulnerability (CWE-601) in versions >=0.4.7 and <0.24.0. The url argument in key partitioning functions is fetched without host validation, enabling attackers who control the URL to cause server-side requests to internal network resources, including loopback addresses and cloud metadata endpoints. The response from these requests is returned as Element text, potentially disclosing sensitive internal information. Side-effecting GET endpoints may also be triggered. This vulnerability is resolved in version 0.24.0.
Potential Impact
An attacker can exploit this vulnerability to make the server-side ingestion service perform unauthorized requests to internal or cloud metadata endpoints, potentially disclosing sensitive internal information through the response body. Additionally, side-effecting GET endpoints may be triggered, which could have further unintended consequences. The CVSS score of 9.3 indicates a critical severity with high confidentiality impact and low integrity impact.
Mitigation Recommendations
Upgrade the unstructured library to version 0.24.0 or later, where this vulnerability has been fixed. No other mitigation is required as the fix addresses the root cause by validating the host in URL fetching.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-06T16:28:51.182Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8730d9acd9273b49e1718f
Added to database: 08/20/2026, 16:52:41 UTC
Last enriched: 09/10/2026, 23:32:03 UTC
Last updated: 10/04/2026, 18:53:18 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.