python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and return their response bodies to the caller.

Project Subscriptions

Vendors Products
Universal-tool-calling-protocol Subscribe
Python-utcp Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 27 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Universal-tool-calling-protocol
Universal-tool-calling-protocol python-utcp
Vendors & Products Universal-tool-calling-protocol
Universal-tool-calling-protocol python-utcp

Sun, 27 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and return their response bodies to the caller.
Title python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T13:11:32.149Z

Reserved: 2026-09-27T16:38:56.428Z

Link: CVE-2026-101060

cve-icon Vulnrichment

Updated: 2026-09-28T13:11:27.813Z

cve-icon NVD

Status : Received

Published: 2026-09-27T18:16:32.273

Modified: 2026-09-28T14:17:13.093

Link: CVE-2026-101060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T19:00:15Z

Weaknesses