unstructured is vulnerable to Allocation of Resources Without Limits or Throttling
30
Low Risk
Affected versions of this package allow decompression of base64+gzipped elements JSON without a strict size cap, enabling a maliciously crafted payload to inflate into extremely large data in memory or on disk. An attacker could exploit this by submitting a compressed payload that expands to hundreds of megabytes or more, triggering excessive memory allocation, filesystem consumption, or process crashes. It can lead to denial-of-service conditions during document ingestion or processing pipelines that deserialize these compressed element payloads.
You are affected if you are using a version that falls within the vulnerable range.
unstructured is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.1.0 - 0.20.7.
Upgrade the unstructured library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant