CVE-2026-101060: python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.calltool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and return their response bodies to the caller.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
python-utcpto a version that resolves this vulnerability.Fixed in 1.1.4
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using python-utcp before 1.1.4 are exposed when they call tools hosted at endpoints an attacker can control. The attacker-controlled endpoint can redirect the UTCP client to internal HTTP services or cloud metadata endpoints.
What does an attacker need to exploit it?
The attacker needs control of a tool endpoint that the affected client will call. They can return an HTTP 302 redirect after the initial tool URL has passed validation.
What can an attacker obtain through the vulnerability?
The UTCP client can be induced to request internal HTTP resources, including cloud metadata endpoints. Response bodies from those requests can be returned to the caller.
Which versions are affected?
python-utcp versions before 1.1.4 are affected.