CPE
The utcp-http library before version 1.1.4 fails to validate the OAuth2 tokenUrl field in remote OpenAPI specifications, allowing attackers to redirect and capture client credentials.