CVE-2026-101059: utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass
utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim's clientid and clientsecret to the attacker-supplied token endpoint without URL validation.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Deployments using utcp-http before 1.1.4 that allow a victim to register or use an attacker-controlled remote OpenAPI specification are exposed. Exploitation occurs when an OAuth2-protected tool generated from that specification is invoked.
What does an attacker need to exploit it?
The attacker needs to supply or cause registration of a malicious OpenAPI specification containing an attacker-selected OAuth2 tokenUrl. They do not need credentials or other privileges according to the provided vector, but the victim must invoke the generated OAuth2-protected tool.
What information can be exposed?
The library can POST the victim's OAuth2 client_id and client_secret to the attacker-controlled token endpoint. The reported impact includes high confidentiality impact and low integrity impact.
How can I tell whether my deployment is affected?
Check whether utcp-http is earlier than version 1.1.4 and whether your workflow accepts remote OpenAPI specifications from untrusted sources. Review registered specifications for OAuth2 tokenUrl values pointing to unexpected or untrusted endpoints.