Description
IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
Published: 2026-09-04
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure
Action: Upgrade immediately
AI Analysis

Impact

The vulnerability is a server‑side request forgery that exploits a DNS Time‑of‑Check to Time‑of‑Use race during tool invocation in IBM ContextForge MCP Gateway versions up to and including 1.0.6. An attacker who can authenticate and create a tool can supply a controlled hostname that rebinding DNS to an internal address, causing the gateway to resolve that hostname and potentially obtain sensitive data. The weakness is classified as CWE‑918 and results in disclosure of confidential information to the authenticated attacker.

Affected Systems

IBM ContextForge MCP Gateway, versions 1.0.6 and earlier, are affected. Only the gateway component is impacted; other IBM ContextForge products are not listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity impact. EPSS data is not available, so the likelihood of exploitation cannot be quantified but the lack of a KEV listing suggests no widespread public exploitation yet. The attack requires authentication and the ability to create a tool, but because the gateway performs DNS resolution on the supplied hostname, an adversary can surf the internal network or exfiltrate data. In environments where least‑privilege access controls are enforced, limiting tool‑creation permissions reduces the attacker’s ability to stage the vulnerability but does not eliminate it.

Generated by OpenCVE AI on September 4, 2026 at 18:20 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<=v1.0.6 https://github.com/IBM/mcp-context-forge/pull/5925_


Vendor Workaround

Workarounds/Mitigation guidance: No complete workaround exists without upgrading. As a partial mitigation, restrict tool-creation permissions (`tools.create`) to fully trusted users only, limiting the pool of accounts that could stage a registration with a controlled hostname. This does not eliminate the vulnerability but reduces exposure in environments where least-privilege access controls are enforced. IBM strongly recommends upgrading to v1.0.7 or higher.


OpenCVE Recommended Actions

  • Upgrade IBM ContextForge MCP Gateway to version 1.0.7 or higher.
  • If an upgrade is not possible, restrict the tools.create permission to fully trusted accounts only, thereby limiting the pool of users that can register a tool with a controlled hostname.
  • Audit existing accounts to ensure that only authorized users have the tools.create capability and remove any unnecessary privileges.
  • For environments that cannot immediately upgrade or restrict permissions, monitor DNS traffic from the gateway for suspicious queries originating during tool creation events.

Generated by OpenCVE AI on September 4, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Ibm contextforge
CPEs cpe:2.3:a:ibm:contextforge:*:*:*:*:*:python:*:*
Vendors & Products Ibm contextforge

Fri, 04 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
Title IBM ContextForge MCP Gateway is affected by server-side request forgery via DNS TOCTOU at tool invocation
First Time appeared Ibm
Ibm contextforge-mcp-gateway
Weaknesses CWE-918
CPEs cpe:2.3:a:ibm:contextforge-mcp-gateway:*:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm contextforge-mcp-gateway
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ibm Contextforge Contextforge-mcp-gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T18:24:43.388Z

Reserved: 2026-08-04T20:21:18.671Z

Link: CVE-2026-18905

cve-icon Vulnrichment

Updated: 2026-09-04T17:40:00.705Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T16:17:21.517

Modified: 2026-09-15T15:21:14.713

Link: CVE-2026-18905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T20:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)