CVE-2026-101060 HIGH

CVE-2026-101060: python-utcp before 1.1.4 SSRF via unvalidated HTTP redirects

Vendor Universal-Tool-Calling-Protocol
Product python-utcp
Weakness CWE-918 · SSRF
Published September 27, 2026
Last update September 27, 2026

CVSS base score

8.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

What the vulnerability does

01Description

python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and return their response bodies to the caller.

Key dates

02Disclosure timeline

September 27, 2026 CVE published

Related vulnerabilities

04Related CVE