PT-2026-99572 · Pypi · Python-Utcp

·

CVE-2026-101060

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions python-utcp versions prior to 1.1.4
Description An issue exists in the call tool() function of the HttpCommunicationProtocol where the initial tool URL is validated, but subsequent HTTP redirects are followed without re-validating the target. This allows an attacker controlling a tool endpoint to issue a 302 redirect to internal services, enabling the client to access cloud metadata endpoints or internal HTTP services and return the response bodies to the caller. This is a server-side request forgery, a flaw where a server is tricked into making requests to an unintended location.
Recommendations Update python-utcp to version 1.1.4 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101060

Affected Products

Python-Utcp