ZeroHour

CVE-2026-77822

niche

Authenticated SSRF via DNS Rebinding in IBM ContextForge MCP Gateway

CVSS 3.1
9.6 critical
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-77822 is a server-side request forgery (CWE-918) in IBM ContextForge MCP Gateway that abuses DNS rebinding: a remote authenticated user can get the gateway to resolve a hostname under their influence and then change that hostname's DNS answer, so the gateway's outbound request is redirected to internal or otherwise restricted resources. Because the SSRF validation happens before the rebinding, the crafted request bypasses URL checks and is issued from the gateway's trusted network position. The attacker can obtain sensitive information from systems reachable by the gateway; the CVSS 3.1 scoring (attack complexity high, low privileges required, no user interaction, scope changed, high confidentiality and integrity impact, no availability impact) indicates the flaw is rated high severity and that requests can affect components beyond the gateway process itself. Organizations running IBM ContextForge MCP Gateway are affected, and an authenticated, low-privileged account on the gateway is required. There is currently no evidence of exploitation: EPSS is 0.2% (11th percentile), the flaw is not in CISA KEV, and no public proof-of-concept is known.

What to do: Monitor the IBM security bulletin for CVE-2026-77822 and upgrade ContextForge MCP Gateway to the fixed release once IBM publishes one, since no fixed version is identified in the available data. Until patched, restrict which accounts can trigger outbound URL fetches and apply egress controls that defeat rebinding (e.g., resolve hostnames once before validation, block external hostnames whose DNS answers later resolve to internal/RFC1918 addresses, and limit the gateway's access to internal-only hosts). Inventory your deployment to confirm which instances are reachable remotely, since exploitation requires network access to the gateway plus valid low-privileged credentials.

Affected
IBM ContextForge MCP Gateway
Estimated exposure
nichelikely hundreds to low thousands of self-hosted enterprise deployments (estimate; no public install or scan telemetry) — ContextForge MCP Gateway is a specialized, recently introduced self-hosted gateway for the Model Context Protocol with no public install counts or internet-exposure scan data available, so the estimate reflects typical early-adopter…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.

Vendors
ibm
Products
contextforge
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.