PT-2026-99571 · Unknown · @Utcp/Http

·

CVE-2026-101059

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions utcp-http versions prior to 1.1.4
Description The library fails to validate the tokenUrl field within remote OpenAPI specifications. This allows an attacker to redirect the submission of credentials to arbitrary endpoints. If a user registers an attacker-controlled OpenAPI specification and invokes a generated OAuth2-protected tool, the library sends the client id and client secret via a POST request to the attacker-supplied token endpoint.
Recommendations Update to version 1.1.4 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101059

Affected Products

@Utcp/Http