CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101058

MEDIUMCVSS 6.9NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-101058 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101058

MEDIUMCVSS 6.9NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]