Skip to main content

CVE-2026-101058: Server-Side Request Forgery (SSRF) in universal-tool-calling-protocol python-utcp

0
High
VulnerabilityCVE-2026-101058cvecve-2026-101058
Published: 09/27/2026 (09/27/2026, 17:02:39 UTC)
Source: CVE Database V5
Vendor/Project: universal-tool-calling-protocol
Product: python-utcp

Description

A Server-Side Request Forgery (SSRF) vulnerability exists in python-utcp (pip package utcp-http) versions before 1.1.12. The vulnerability allows an attacker who can serve a UTCP manual to cause the client to send requests to services bound to the loopback interface (127.0.0.1) on the victim host. This occurs because the software does not verify whether tool URLs declared in a manually written UTCP manual fetched from a non-loopback origin point to the loopback interface. The affected protocols include http, sse, and streamable_http. Exploitation requires a loopback service that responds to unauthenticated requests with useful data. The issue is fixed in version 1.1.12, which rejects manuals fetched from non-loopback origins that declare loopback tool URLs.

CVSS v4.0

Score 7.1high

Attack Vector
Network
Attack Complexity
High
Attack Requirements
Present
Privileges Required
None
User Interaction
Passive
Vuln. Confidentiality
High
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
Low
Subsq. Availability
None
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

Affected software

universal-tool-calling-protocol

python-utcp

Affected versions
>=0 <1.1.12
utcp-http
pkg:pypi/utcp-http
Affected versions
<1.1.12

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 01:59:02 UTC

Technical Analysis

python-utcp (utcp-http) before version 1.1.12 does not properly validate tool URLs in UTCP manuals fetched from remote origins, allowing SSRF attacks targeting the loopback interface. The vulnerability arises because ensure_secure_url permits loopback HTTP for local development, and native manuals bypass the loopback check performed by the OpenAPI converter. An attacker able to serve a UTCP manual that a victim registers can cause the client to issue requests to 127.0.0.1 services and receive response bodies, potentially exposing sensitive local services. The vulnerability affects the http, sse, and streamable_http protocols. The fix in 1.1.12 rejects manuals from non-loopback origins that declare loopback URLs, based on the final post-redirect discovery URL.

Potential Impact

An attacker who can serve a malicious UTCP manual to a victim can induce the victim's client to send requests to local loopback services (127.0.0.1) that may be otherwise inaccessible remotely. This can lead to unauthorized disclosure of data from local services that respond to unauthenticated requests. The reach of the attack is limited to the loopback interface, and exploitation requires the presence of vulnerable local services. There are no known exploits in the wild at this time.

Mitigation Recommendations

A fix is available in python-utcp (utcp-http) version 1.1.12. Users should upgrade to version 1.1.12 or later, which rejects UTCP manuals fetched from non-loopback origins that declare loopback tool URLs. No additional mitigation is required if the software is updated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-27T16:38:56.428Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab9c996f7a7c54106f51d5f

Added to database: 09/28/2026, 01:57:42 UTC

Last enriched: 09/28/2026, 01:59:02 UTC

Last updated: 09/28/2026, 02:07:42 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses