CVE-2026-101061: utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass

Published Sep 27, 2026
·
Updated

utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin performs no URL validation despite documented security requirements. Attackers can force connections to internal services and cloud metadata endpoints by supplying malicious tool URLs in call templates, and receive configured API keys and OAuth tokens sent to attacker-controlled hosts.

Affected Software

2 affected components
utcp-gql<1.1.1
utcp-websocket<1.1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade utcp-gql and utcp-websocket to a version that resolves this vulnerability.

    Fixed in 1.1.1

Event History

Sep 27, 2026
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments should be prioritized for remediation?

Deployments using utcp-gql or utcp-websocket versions earlier than 1.1.1 should be prioritized, especially where tool URLs can be supplied through call templates and the service can reach internal networks or cloud metadata endpoints.

2

What does an attacker need to exploit this issue?

An attacker needs to supply a malicious tool URL in a call template and induce the affected plugin to use it. No authentication privilege is required, but exploitation requires user interaction and has high attack complexity.

3

How do the affected plugins differ in their exposure?

In utcp-gql, URL validation relies on a vulnerable prefix check that can be bypassed with hosts such as 127.0.0.1.attacker.example. In utcp-websocket, no URL validation is performed despite the documented security requirement.

4

What sensitive data could be exposed through a successful exploit?

The affected plugins can be made to connect to attacker-controlled hosts and send configured API keys and OAuth tokens. They can also be used to reach internal services and cloud metadata endpoints.

5

How can teams determine whether they are affected?

Identify installations of utcp-gql or utcp-websocket earlier than version 1.1.1, then review whether call templates permit attacker-influenced tool URLs. Instances with configured API keys or OAuth tokens and network access to internal or cloud metadata services have greater impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203