CVE-2026-101058: python-utcp before 1.1.12 SSRF via Remote HTTP Manual

Published Sep 27, 2026
·
Updated

python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensuresecureurl intentionally permits loopback HTTP for local development and native manuals bypassed the loopback check performed by the OpenAPI converter, an attacker who can serve a UTCP manual that a victim registers can cause the client to issue requests to services bound only to 127.0.0.1 on the victim host and have the response bodies returned to the caller (server-side request forgery). The http, sse and streamablehttp protocols are all affected. Reach is limited to loopback, and exploitation further requires a loopback service that answers unauthenticated requests with useful data. Fixed in utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs, keyed off the final post-redirect discovery URL.

Affected Software

1 affected component
pypi/utcp-http<1.1.12

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade utcp-http to a version that resolves this vulnerability.

    Fixed in 1.1.12

Event History

Sep 27, 2026
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are realistically exposed?

Clients using utcp-http before 1.1.12 are exposed when they register a hand-written UTCP manual discovered from a remote, non-loopback origin. The issue affects the http, sse, and streamable_http protocols.

2

What must an attacker be able to do to exploit this?

An attacker must be able to serve a UTCP manual that the victim registers. The manual must declare tool URLs targeting the victim host's loopback interface, and a loopback-only service must return useful data without authentication.

3

What is the reachable network scope and potential impact?

Reach is limited to services bound to 127.0.0.1 on the victim host. Successful exploitation can cause the client to request those services and return their response bodies to the caller; the described impact includes high confidentiality impact and low integrity impact.

4

How can this be remediated?

Upgrade utcp-http to version 1.1.12. This version rejects remote-origin manuals that declare loopback tool URLs, using the final discovery URL after redirects.

5

What can be done if upgrading is not immediately possible?

Do not register hand-written UTCP manuals obtained from remote, non-loopback origins when they declare tool URLs pointing to loopback addresses. Restrict registrations to trusted manuals and avoid exposing useful unauthenticated services on 127.0.0.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203