Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-8cp3-qxj6-px34
  • PyPI/utcp-http
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion 25 Aug
  • Fix available
  • Severity - 7.1 (High)
GHSA-9qhg-99ww-9mqc
  • PyPI/utcp-http
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target 25 Aug
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-3396
  • PyPI/utcp-http
utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol 13 Jul
  • Fix available
  • Severity - 4.7 (Medium)
GHSA-39j6-4867-gg4w
  • PyPI/utcp-http
utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol 07 May
  • Fix available
  • Severity - 4.7 (Medium)