unstructured 0.21.0
UpdateUnverifiedAdded Sep 25, 2026
0.21.0 Fixes - Replace NLTK with spaCy to remediate CVE-2025-14009: NLTK's downloader uses zipfile.extractall() without path validation, enabling RCE via malicious packages (CVSS 10.0, no patch available). spaCy models install as pip packages, eliminating the vulnerable downloader entirely.
Topics: Security
More releases
Every release| Date | Release | Type |
|---|---|---|
| Feb 22 | unstructured 0.21.1unverified Update | Update |
| Feb 23 | unstructured 0.21.2unverified Update | Update |
| Feb 24 | unstructured 0.21.5unverified Update | Update |
| Feb 20 | unstructured 0.20.8unverified Update | Update |
| Feb 19 | unstructured 0.20.6unverified Update | Update |
| Feb 13 | unstructured 0.20.2unverified Update | Update |
| Feb 12 | unstructured 0.20.1unverified Update | Update |
| Feb 11 | unstructured 0.19.3unverified Update | Update |
Also shipped on Feb 22, 2026
in February 2026| Date | Company | Release | Product | Type |
|---|---|---|---|---|
| Feb 22 | feldera | feldera 0.250.0unverified | feldera | Update |
Sources: each vendor's own release notes, changelogs and GitHub releases, read daily to monthly by how often it posts. Logos via logo.dev; trademarks belong to their owners.