CVE-2026-77822
nicheAuthenticated SSRF via DNS Rebinding in IBM ContextForge MCP Gateway
CVE-2026-77822 is a server-side request forgery (CWE-918) in IBM ContextForge MCP Gateway that abuses DNS rebinding: a remote authenticated user can get the gateway to resolve a hostname under their influence and then change that hostname's DNS answer, so the gateway's outbound request is redirected to internal or otherwise restricted resources. Because the SSRF validation happens before the rebinding, the crafted request bypasses URL checks and is issued from the gateway's trusted network position. The attacker can obtain sensitive information from systems reachable by the gateway; the CVSS 3.1 scoring (attack complexity high, low privileges required, no user interaction, scope changed, high confidentiality and integrity impact, no availability impact) indicates the flaw is rated high severity and that requests can affect components beyond the gateway process itself. Organizations running IBM ContextForge MCP Gateway are affected, and an authenticated, low-privileged account on the gateway is required. There is currently no evidence of exploitation: EPSS is 0.2% (11th percentile), the flaw is not in CISA KEV, and no public proof-of-concept is known.
What to do: Monitor the IBM security bulletin for CVE-2026-77822 and upgrade ContextForge MCP Gateway to the fixed release once IBM publishes one, since no fixed version is identified in the available data. Until patched, restrict which accounts can trigger outbound URL fetches and apply egress controls that defeat rebinding (e.g., resolve hostnames once before validation, block external hostnames whose DNS answers later resolve to internal/RFC1918 addresses, and limit the gateway's access to internal-only hosts). Inventory your deployment to confirm which instances are reachable remotely, since exploitation requires network access to the gateway plus valid low-privileged credentials.
| IBM ContextForge MCP Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
- Vendors
- ibm
- Products
- contextforge
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.