PT-2026-99572 · Pypi · Python-Utcp
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
python-utcp versions prior to 1.1.4
Description
An issue exists in the
call tool() function of the HttpCommunicationProtocol where the initial tool URL is validated, but subsequent HTTP redirects are followed without re-validating the target. This allows an attacker controlling a tool endpoint to issue a 302 redirect to internal services, enabling the client to access cloud metadata endpoints or internal HTTP services and return the response bodies to the caller. This is a server-side request forgery, a flaw where a server is tricked into making requests to an unintended location.Recommendations
Update python-utcp to version 1.1.4 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python-Utcp