unstructured
Convert documents to structured data effortlessly. Unstructured is open-source ETL solution for transforming complex documents into clean, structured formats for language models. Visit our website to learn more about our enterprise grade Platform product for production grade workflows, partitioning, enrichments, chunking and embedding.
Activity
- Latest release
- 5h ago
- Total releases
- 233
- Cadence
- ~5 days
- Last 12 months
- 40
Reach
- Stars
- 15.4k
Details
- License
- Apache-2.0
- First release
- Sep 06, 2022
| Version | Released | |
|---|---|---|
0.27.6
patch
|
0.27.6
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
0.27.5
patch
|
0.27.5
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
0.27.1
minor
|
0.27.1
minor
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
0.25.2
patch
|
0.25.2
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
0.25.0
minor
|
0.25.0
minor
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
0.24.1
patch
|
0.24.1
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
0.24.0
minor
|
0.24.0
minor
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.23.1
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.23.1
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.23.0
minor
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.23.0
minor
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.32
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.32
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.31
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.31
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.30
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.30
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.29
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.29
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.28
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.28
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.27
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.27
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.26
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.26
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.23
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.23
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.22
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.22
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.21
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.21
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.20
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.20
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.18
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.18
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.16
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.16
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.12
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.12
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.10
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.10
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.22.6
minor
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.22.6
minor
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.21.5
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.21.5
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.21.2
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.21.2
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.21.1
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.21.1
patch
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.21.0
minor
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.21.0
minor
Dependencies (46)
+ 38 more
Changelog
Compare changes
|
|
0.20.8
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.20.8
patch
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.20.6
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.20.6
patch
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.20.2
minor
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.20.2
minor
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
0.18.32
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.18.31
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.18.27
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.18.26
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.18.24
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.18.21
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.18.20
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.18.18
patch
1 CVE
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.18.15
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.14
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.13
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.11
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.9
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.7
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.6
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.5
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.3
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.18.2
patch
2 CVEs
CVE-2026-71428
PYSEC-2026-3930
GHSA-4mvj-m6j5-pmf7
Sep 10, 2026
unstructured: Server-Side Request Forgery in the URL-based partitioning
9.3
/ 10
Critical
Network
Low
None
None
Changed
High
Low
None
SummaryServer-Side Request Forgery in
DetailsThree sinks, all in
None of PoCLocal-only.
In production the attacker substitutes ImpactAttacker capabilities:
Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
0.10.19.dev18
+ 194 more Show less
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.18
0.18.2
0.18.20
0.18.21
0.18.24
0.18.26
0.18.27
0.18.3
0.18.31
0.18.32
0.18.5
0.18.6
0.18.7
0.18.9
0.20.2
0.20.6
0.20.8
0.21.0
0.21.1
0.21.2
0.21.5
0.22.10
0.22.12
0.22.16
0.22.18
0.22.20
0.22.21
0.22.22
0.22.23
0.22.26
0.22.27
0.22.28
0.22.29
0.22.30
0.22.31
0.22.32
0.22.6
0.23.0
0.23.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.24.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-64712
PYSEC-2026-558
GHSA-gm8q-m8mv-jj5m
Jun 29, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A Path Traversal vulnerability in the ImpactAn attacker can craft a malicious .msg file with attachment filenames containing path traversal sequences (e.g.,
Affected FunctionalityThe vulnerability affects the MSG file partitioning functionality when Vulnerability DetailsThe library does not sanitize attachment filenames in MSG files before using them in file write operations, allowing directory traversal sequences to escape the intended output directory. WorkaroundsUntil patched, users can:
Affected versions
0.0.1.dev0
0.10.0
0.10.1
0.10.10
0.10.11
0.10.12
0.10.13
0.10.14
0.10.15
0.10.16
0.10.18
0.10.19
+ 181 more Show less
0.10.19.dev18
0.10.2
0.10.20
0.10.21
0.10.22
0.10.23
0.10.24
0.10.25
0.10.26
0.10.27
0.10.28
0.10.29
0.10.30
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.11.0
0.11.1
0.11.2
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.12.0
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.13.5
0.13.6
0.13.7
0.14.0
0.14.10
0.14.2
0.14.2.dev1
0.14.3
0.14.4
0.14.5
0.14.6
0.14.7
0.14.8
0.14.9
0.15.0
0.15.1
0.15.10
0.15.12
0.15.13
0.15.14
0.15.3
0.15.5
0.15.6
0.15.7
0.15.8
0.15.9
0.16.0
0.16.1
0.16.10
0.16.11
0.16.12
0.16.13
0.16.14
0.16.15
0.16.16
0.16.17
0.16.19
0.16.2
0.16.20
0.16.21
0.16.22
0.16.23
0.16.24
0.16.25
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.16.8
0.16.9
0.17.0
0.17.2
0.18.1
0.18.11
0.18.13
0.18.14
0.18.15
0.18.2
0.18.3
0.18.5
0.18.6
0.18.7
0.18.9
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6.dev1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.15
0.4.16
0.4.2
0.4.3
0.4.4
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.2
0.5.3
0.5.4
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
0.6.1
0.6.10
0.6.11
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
0.8.8
0.9.0
0.9.1
0.9.2
0.9.3
Fixed in
0.18.18
References
Updated Jul 13, 2026 · Source: OSV.dev |