{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3autcputcp-http/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:utcp:utcp-http:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-101059"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["utcp-http (\u003c 1.1.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["utcp"],"content_html":"\u003cp\u003eThe utcp-http library, version 1.1.4 and prior, contains a critical vulnerability related to the improper validation of the OAuth2 tokenUrl field retrieved from remote OpenAPI specifications. When a developer or user registers a malicious or compromised OpenAPI specification, the library blindly processes the provided tokenUrl value. Upon invoking a tool generated from this specification, the library performs an automated HTTP POST request to the attacker-defined endpoint. This request includes the victim's client_id and client_secret credentials, effectively exfiltrating them to an arbitrary destination under the attacker's control. This vulnerability poses a significant risk to applications relying on utcp-http for OAuth2-protected tool integration, as it facilitates credential theft through the manipulation of remote schema definitions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the theft of OAuth2 client_id and client_secret credentials, potentially leading to unauthorized access to downstream services or APIs protected by these credentials. If the stolen credentials provide broad permissions, the impact could extend to significant data exposure or unauthorized actions within the victim's integrated services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the utcp-http library to version 1.1.4 or later immediately to incorporate necessary URL validation logic.\u003c/li\u003e\n\u003cli\u003eAudit all currently registered or dynamically loaded OpenAPI specifications to ensure that the tokenUrl fields point to trusted and expected domains.\u003c/li\u003e\n\u003cli\u003eImplement strict allowlisting for domains allowed in the OAuth2 configuration if dynamic remote specification loading is required.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T19:09:13Z","date_published":"2026-09-27T19:09:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-utcp-http-auth-bypass/","summary":"The utcp-http library before version 1.1.4 fails to validate the OAuth2 tokenUrl field in remote OpenAPI specifications, allowing attackers to redirect and capture client credentials.","title":"Credential Exfiltration via Unvalidated OAuth2 TokenUrl in utcp-http","url":"https://feed.craftedsignal.io/briefs/2026-09-utcp-http-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:utcp:utcp-Http:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}