CVE-2026-101060

CVE-2026-101060 published: python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoi...

View full NVD advisory → ← Back to CVE watch