THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9qhg-99ww-9mqc (high) — utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

[GHSA] GHSA-9qhg-99ww-9mqc (high) — utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

highgithub_advisoriesPublished 2026-08-25

GHSA-9qhg-99ww-9mqc Severity: high CVE: None

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

## Summary

`HttpCommunicationProtocol.call_tool` validates only the pre-redirect tool URL, then issues the request with redirects enabled and never re-checks where it lands. A tool whose endpoint is an attacker-controlled public URL can therefore `302`-redirect th

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9qhg-99ww-9mqc