CVE-2026-101059: utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass

Published Sep 27, 2026
·
Updated

utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library POSTs the victim's clientid and clientsecret to the attacker-supplied token endpoint without URL validation.

Affected Software

1 affected component
pypi/utcp-http<1.1.4

Event History

Sep 27, 2026
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Deployments using utcp-http before 1.1.4 that allow a victim to register or use an attacker-controlled remote OpenAPI specification are exposed. Exploitation occurs when an OAuth2-protected tool generated from that specification is invoked.

2

What does an attacker need to exploit it?

The attacker needs to supply or cause registration of a malicious OpenAPI specification containing an attacker-selected OAuth2 tokenUrl. They do not need credentials or other privileges according to the provided vector, but the victim must invoke the generated OAuth2-protected tool.

3

What information can be exposed?

The library can POST the victim's OAuth2 client_id and client_secret to the attacker-controlled token endpoint. The reported impact includes high confidentiality impact and low integrity impact.

4

How can I tell whether my deployment is affected?

Check whether utcp-http is earlier than version 1.1.4 and whether your workflow accepts remote OpenAPI specifications from untrusted sources. Review registered specifications for OAuth2 tokenUrl values pointing to unexpected or untrusted endpoints.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203