utcp-http vulnerabilities
CVEs whose affected-version data names the utcp-http package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
GHSA-9qhg-99ww-9mqcHigh· 8.2utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
▾ Twilightutcp-http · utcp-httpvia GHSA
GHSA-8cp3-qxj6-px34High· 7.1utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
▾ Twilightutcp-http · utcp-httpvia GHSA
CVE-2026-44661Medium· 4.7utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol
utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol
▾ Sunlitutcp-http · utcp-httpEPSS 0.17%via OSV