Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101058— python-utcp before 1.1.12 SSRF via Remote HTTP Manual

Quick assessment

Affected
universal-tool-calling-protocol python-utcp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 utcp-http(pip 包)1.1.12 版本之前,存在一个安全漏洞。该漏洞未验证由用户手动编写的 UTCP 手册中声明的工具 URL 是否指向代理自身的回环接口(loopback interface),特别是在这些手册是从远程(非回环)源被发现的情况下。 由于 故意允许用于本地开发的回环 HTTP 请求,而本机手册绕过了 OpenAPI 转换器所执行的回环检查,攻击者可以提供一份 UTCP 手册供受害者注册,从而诱导客户端向仅绑定到 127.0.0.1 的目标主机上的服务发起请求,并将响应体返回给调用方(

CVSS 6.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101058

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
python-utcp before 1.1.12 SSRF via Remote HTTP Manual
Source: CVE Program / CVE List V5
Vulnerability Description
python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for local development and native manuals bypassed the loopback check performed by the OpenAPI converter, an attacker who can serve a UTCP manual that a victim registers can cause the client to issue requests to services bound only to 127.0.0.1 on the victim host and have the response bodies returned to the caller (server-side request forgery). The http, sse and streamable_http protocols are all affected. Reach is limited to loopback, and exploitation further requires a loopback service that answers unauthenticated requests with useful data. Fixed in utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs, keyed off the final post-redirect discovery URL.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
universal-tool-calling-protocol python-utcp 0 ~ 1.1.12 -

II. Public POCs for CVE-2026-101058

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101058

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101058 (1)

Other References for CVE-2026-101058 (1)

Same Patch Batch · universal-tool-calling-protocol · 2026-09-27 · 5 CVEs total

CVE-2026-101060 8.2 HIGH python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects
CVE-2026-101059 7.1 HIGH utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass
CVE-2026-101061 4.7 MEDIUM utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass
CVE-2026-101057 3.1 LOW utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL

IV. Related Vulnerabilities

V. Comments for CVE-2026-101058

No comments yet


Leave a comment