Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101060— python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects

Quick assessment

Affected
universal-tool-calling-protocol python-utcp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 python-utcp 1.1.4 之前的版本中,HttpCommunicationProtocol.call_tool 存在服务器端请求伪造(SSRF)漏洞。该函数虽然对初始工具 URL 进行了验证,但在跟随 HTTP 重定向时未重新验证目标地址。攻击者若能控制工具端点,即可返回一个 302 重定向响应,将 UTCP 客户端重定向至内部服务或云元数据端点,并获取这些内部服务的响应内容返回给调用者。

CVSS 8.2 · High

Possible ATT&CK Techniques 1 AI

T1071.002 · File Transfer Protocols
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101060

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects
Source: CVE Program / CVE List V5
Vulnerability Description
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and return their response bodies to the caller.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
universal-tool-calling-protocol python-utcp 0 ~ 1.1.4 -

II. Public POCs for CVE-2026-101060

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101060

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101060 (1)

Other References for CVE-2026-101060 (1)

Same Patch Batch · universal-tool-calling-protocol · 2026-09-27 · 5 CVEs total

CVE-2026-101059 7.1 HIGH utcp-http before 1.1.4 OAuth2 tokenUrl Trust Boundary Bypass
CVE-2026-101058 6.9 MEDIUM python-utcp before 1.1.12 SSRF via Remote HTTP Manual
CVE-2026-101061 4.7 MEDIUM utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass
CVE-2026-101057 3.1 LOW utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL

IV. Related Vulnerabilities

V. Comments for CVE-2026-101060

No comments yet


Leave a comment