ZeroHour

CVE-2026-18905

niche

DNS rebinding information disclosure in IBM ContextForge MCP Gateway 1.0.6 and earlier

CVSS 3.1
7.7 high
EPSS
<1%p23
Published
()
Modified
AI analysis

IBM ContextForge MCP Gateway (mcp-contextforge-gateway) versions through 1.0.6 contain a DNS rebinding vulnerability (CWE-918, SSRF-related) in how the gateway performs server-side requests during MCP tool invocation. A remote attacker with valid credentials can direct the gateway to a hostname they control; the name initially resolves to an allowed external address and then rebinds to an internal address such as loopback or a private-network service, causing the gateway itself to fetch internal resources on the attacker's behalf. The fetched content is returned to the attacker, resulting in disclosure of sensitive internal information (CVSS 3.1 7.7 High: high confidentiality impact, no integrity or availability impact, scope change). Any deployment running mcp-contextforge-gateway 1.0.6 or earlier is affected; authentication is required, so exposure is limited to environments where the attacker can authenticate. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists; EPSS currently estimates roughly a 0.3% probability of exploitation within 30 days.

What to do: Upgrade mcp-contextforge-gateway to a release newer than 1.0.6 once IBM publishes the fixed version, and check the IBM security advisory for the exact fixed release. As an interim mitigation, restrict tool-invocation allowlists to trusted external endpoints, block the gateway from resolving hostnames to loopback/link-local/private addresses (or pin DNS records for allowed hosts), and review which authenticated users can register or invoke tools against attacker-controlled URLs. No active exploitation is known, so patching can follow normal maintenance cycles, but prioritize internet-facing or multi-tenant deployments.

Affected
IBM ContextForge MCP Gateway (mcp-contextforge-gateway)<= 1.0.6 (all versions up to and including 1.0.6; fixed version not stated in available data)
Estimated exposure
nichelikely hundreds to low thousands of deployments (early-adopter AI infrastructure; no published install counts) — No public install statistics exist for this recently released, specialized MCP gateway, so the estimate reflects its niche role in early AI-agent stacks rather than measured adoption.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.

Vendors
ibm
Products
contextforge
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.