Threat Advisory

UTCP Vulnerability Reveals Logic Gaps in Tool Setup Configurations

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-12210 with a CVSS score of 4.7 affects the utcp-gql and utcp-websocket packages due to incomplete remediation of a Server-Side Request Forgery (SSRF) vulnerability caused by improper URL validation. The GraphQL plugin continued using a vulnerable prefix-based URL check that allowed attacker-controlled domains to bypass localhost restrictions. Additionally, the WebSocket plugin lacked any URL validation despite claiming to enforce secure connections, allowing attackers to initiate connections to internal services, loopback addresses, or cloud metadata endpoints. Because both plugins attach configured authentication headers, including API keys, Basic authentication credentials, and OAuth bearer tokens, successful exploitation could result in internal network access and credential leakage to attacker-controlled systems. The vulnerability has been addressed by implementing proper hostname-based URL validation and preventing unsafe redirects.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-12210 with a CVSS score of 4.7 affects the utcp-gql and utcp-websocket packages due to incomplete remediation of a Server-Side Request Forgery (SSRF) vulnerability caused by improper URL validation. The GraphQL plugin continued using a vulnerable prefix-based URL check that allowed attacker-controlled domains to bypass localhost restrictions. Additionally, the WebSocket plugin lacked any URL validation despite claiming to enforce secure connections, allowing attackers to initiate connections to internal services, loopback addresses, or cloud metadata endpoints. Because both plugins attach configured authentication headers, including API keys, Basic authentication credentials, and OAuth bearer tokens, successful exploitation could result in internal network access and credential leakage to attacker-controlled systems. The vulnerability has been addressed by implementing proper hostname-based URL validation and preventing unsafe redirects.[emaillocker id="1283"]

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-ppx3-28rw-8fpf

[/emaillocker]
crossmenu