CVE-2026-18905
nicheDNS rebinding information disclosure in IBM ContextForge MCP Gateway 1.0.6 and earlier
IBM ContextForge MCP Gateway (mcp-contextforge-gateway) versions through 1.0.6 contain a DNS rebinding vulnerability (CWE-918, SSRF-related) in how the gateway performs server-side requests during MCP tool invocation. A remote attacker with valid credentials can direct the gateway to a hostname they control; the name initially resolves to an allowed external address and then rebinds to an internal address such as loopback or a private-network service, causing the gateway itself to fetch internal resources on the attacker's behalf. The fetched content is returned to the attacker, resulting in disclosure of sensitive internal information (CVSS 3.1 7.7 High: high confidentiality impact, no integrity or availability impact, scope change). Any deployment running mcp-contextforge-gateway 1.0.6 or earlier is affected; authentication is required, so exposure is limited to environments where the attacker can authenticate. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists; EPSS currently estimates roughly a 0.3% probability of exploitation within 30 days.
What to do: Upgrade mcp-contextforge-gateway to a release newer than 1.0.6 once IBM publishes the fixed version, and check the IBM security advisory for the exact fixed release. As an interim mitigation, restrict tool-invocation allowlists to trusted external endpoints, block the gateway from resolving hostnames to loopback/link-local/private addresses (or pin DNS records for allowed hosts), and review which authenticated users can register or invoke tools against attacker-controlled URLs. No active exploitation is known, so patching can follow normal maintenance cycles, but prioritize internet-facing or multi-tenant deployments.
| IBM ContextForge MCP Gateway (mcp-contextforge-gateway) | <= 1.0.6 (all versions up to and including 1.0.6; fixed version not stated in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
- Vendors
- ibm
- Products
- contextforge
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.