PT-2026-99570 · Pypi · @Utcp/Http

·

CVE-2026-101058

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v3.1

6.9

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions python-utcp (pip package utcp-http) versions prior to 1.1.12
Description The software fails to verify if tool URLs in a hand-written UTCP manual point to the agent's own loopback interface when the manual is retrieved from a remote, non-loopback origin. This occurs because the ensure secure url function permits loopback HTTP for local development, and native manuals bypassed the loopback check used by the OpenAPI converter. An attacker providing a malicious UTCP manual can trigger server-side request forgery (SSRF), causing the client to send requests to services bound to 127.0.0.1 on the victim host and return the response bodies to the attacker. This issue affects the http, sse, and streamable http protocols. Exploitation requires a loopback service that responds to unauthenticated requests.
Recommendations Update python-utcp (pip package utcp-http) to version 1.1.12.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101058

Affected Products

@Utcp/Http