Vulnerability  ·  2026-09-28

python-utcp: loopback SSRF when a remote UTCP manual declares loopback tool URLs

VulnerabilityLow impactGlobalCVE-2026-101058
NVD published on 2026-09-27 (VulnCheck): python-utcp before 1.1.12 does not verify that tool URLs in a remote-discovered UTCP manual point at the agent's own loopback interface, enabling loopback SSRF (CVSS 6.9 v3.1).
UTCP is the emerging universal tool-calling protocol for agent connectors; a malicious manual is an untrusted config surface that can redirect an agent's own HTTP-family tool primitives against localhost services on the deploying host — relevant for agent deployments that register third-party tool catalogs.
ensure_secure_url permits loopback HTTP for local dev, and native (hand-written) UTCP manuals bypass the loopback check the OpenAPI converter applies; a remote attacker who serves a manual the victim registers can cause the agent client to issue requests to the victim's localhost-only services and receive the response bodies (SSRF).
universal-tool-calling-protocol/python-utcp (pip utcp-http) < 1.1.12; http, sse, streamable_http protocols
Upgrade to utcp-http 1.1.12, which rejects manuals fetched from a non-loopback origin that declare loopback tool URLs. Advisory: https://github.com/universal-tool-calling-protocol/python-utcp/security/advisories/GHSA-8vxx-v7r9-948g
NVD CVE-2026-101058GitHub Security Advisory GHSA-8vxx-v7r9-948g
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →