Fetching from the wire…
Security2026-08-27 · source-backed
GHSA-8cp3-qxj6-px34 covers utcp-http <= 1.1.3, where OpenApiConverter._extract_auth() reads the OAuth2 tokenUrl straight out of a remote spec and never validates it. The ensure_secure_url() guard the library applies to discovery URLs and tool invocation URLs is simply absent on the token endpoint, so registering an attacker-controlled spec and invoking any generated OAuth2 tool exfiltrates client_id and client_secret (GitHub Advisory). Two companion advisories the same hour: redirect-following without re-validation, and a prior SSRF fix that was never applied to the GraphQL and WebSocket plugins.
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source domain / Shared topic / Tension
Both cover GHSA, GitHub Advisory, SSRF; reported by the same outlet (github.com); overlapping topics (attacker-controlled, endpoint).
Shared entities / Same source domain / Tension
Both cover GHSA, GitHub Advisory, SSRF; reported by the same outlet (github.com); pushes against this story (against).
Shared entities / Same source domain / Earlier coverage
Both cover SSRF, WebSocket; reported by the same outlet (github.com); earlier SSRF coverage from 2026-08-15.
Both cover URLs, WebSocket; reported by the same outlet (github.com); earlier URLs coverage from 2026-07-30.
Both cover OAuth2, OpenAPI; reported by the same outlet (github.com); earlier OAuth2 coverage from 2026-07-16.
Both cover GHSA, GitHub Advisory; reported by the same outlet (github.com); earlier GHSA coverage from 2026-02-27.
Both cover GHSA, URLs; reported by the same outlet (github.com); earlier GHSA coverage from 2026-02-24.
Shared entity: GHSA / Same source domain / Shared topic / Earlier coverage
Both cover GHSA; reported by the same outlet (github.com); overlapping topics (advisory, tool).