CVE-2026-101058: Server-Side Request Forgery (SSRF) in universal-tool-calling-protocol python-utcp
A Server-Side Request Forgery (SSRF) vulnerability exists in python-utcp (pip package utcp-http) versions before 1.1.12. The vulnerability allows an attacker who can serve a UTCP manual to cause the client to send requests to services bound to the loopback interface (127.0.0.1) on the victim host. This occurs because the software does not verify whether tool URLs declared in a manually written UTCP manual fetched from a non-loopback origin point to the loopback interface. The affected protocols include http, sse, and streamable_http. Exploitation requires a loopback service that responds to unauthenticated requests with useful data. The issue is fixed in version 1.1.12, which rejects manuals fetched from non-loopback origins that declare loopback tool URLs.
AI Analysis
Technical Summary
python-utcp (utcp-http) before version 1.1.12 does not properly validate tool URLs in UTCP manuals fetched from remote origins, allowing SSRF attacks targeting the loopback interface. The vulnerability arises because ensure_secure_url permits loopback HTTP for local development, and native manuals bypass the loopback check performed by the OpenAPI converter. An attacker able to serve a UTCP manual that a victim registers can cause the client to issue requests to 127.0.0.1 services and receive response bodies, potentially exposing sensitive local services. The vulnerability affects the http, sse, and streamable_http protocols. The fix in 1.1.12 rejects manuals from non-loopback origins that declare loopback URLs, based on the final post-redirect discovery URL.
Potential Impact
An attacker who can serve a malicious UTCP manual to a victim can induce the victim's client to send requests to local loopback services (127.0.0.1) that may be otherwise inaccessible remotely. This can lead to unauthorized disclosure of data from local services that respond to unauthenticated requests. The reach of the attack is limited to the loopback interface, and exploitation requires the presence of vulnerable local services. There are no known exploits in the wild at this time.
Mitigation Recommendations
A fix is available in python-utcp (utcp-http) version 1.1.12. Users should upgrade to version 1.1.12 or later, which rejects UTCP manuals fetched from non-loopback origins that declare loopback tool URLs. No additional mitigation is required if the software is updated.
CVE-2026-101058: Server-Side Request Forgery (SSRF) in universal-tool-calling-protocol python-utcp
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in python-utcp (pip package utcp-http) versions before 1.1.12. The vulnerability allows an attacker who can serve a UTCP manual to cause the client to send requests to services bound to the loopback interface (127.0.0.1) on the victim host. This occurs because the software does not verify whether tool URLs declared in a manually written UTCP manual fetched from a non-loopback origin point to the loopback interface. The affected protocols include http, sse, and streamable_http. Exploitation requires a loopback service that responds to unauthenticated requests with useful data. The issue is fixed in version 1.1.12, which rejects manuals fetched from non-loopback origins that declare loopback tool URLs.
CVSS v4.0
Score 7.1high
Affected software
universal-tool-calling-protocol
python-utcp
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
python-utcp (utcp-http) before version 1.1.12 does not properly validate tool URLs in UTCP manuals fetched from remote origins, allowing SSRF attacks targeting the loopback interface. The vulnerability arises because ensure_secure_url permits loopback HTTP for local development, and native manuals bypass the loopback check performed by the OpenAPI converter. An attacker able to serve a UTCP manual that a victim registers can cause the client to issue requests to 127.0.0.1 services and receive response bodies, potentially exposing sensitive local services. The vulnerability affects the http, sse, and streamable_http protocols. The fix in 1.1.12 rejects manuals from non-loopback origins that declare loopback URLs, based on the final post-redirect discovery URL.
Potential Impact
An attacker who can serve a malicious UTCP manual to a victim can induce the victim's client to send requests to local loopback services (127.0.0.1) that may be otherwise inaccessible remotely. This can lead to unauthorized disclosure of data from local services that respond to unauthenticated requests. The reach of the attack is limited to the loopback interface, and exploitation requires the presence of vulnerable local services. There are no known exploits in the wild at this time.
Mitigation Recommendations
A fix is available in python-utcp (utcp-http) version 1.1.12. Users should upgrade to version 1.1.12 or later, which rejects UTCP manuals fetched from non-loopback origins that declare loopback tool URLs. No additional mitigation is required if the software is updated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-27T16:38:56.428Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab9c996f7a7c54106f51d5f
Added to database: 09/28/2026, 01:57:42 UTC
Last enriched: 09/28/2026, 01:59:02 UTC
Last updated: 09/28/2026, 02:07:42 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.