Description
ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls validate_gateway_test_url() in mcpgateway/common/validators.py to resolve and reject private, loopback, link-local, and cloud-metadata addresses, but ResilientHttpClient later resolves the original hostname again without binding the validated address. When MCPGATEWAY_ADMIN_API_ENABLED is enabled, an attacker with a database-backed role containing explicit gateways.read permission can use DNS rebinding to return a public address during validation and a private or metadata address during connection, bypassing ssrf_blocked_networks and ssrf_dns_fail_closed because those controls apply only to the validation-time result. The endpoint's allow_admin_bypass=False setting means a bootstrap-only virtual platform-admin identity without a database role is not sufficient. Successful exploitation can reach internal services and cloud metadata, expose cloud credentials, access internal APIs, or probe internal network ports. This issue is fixed in version 1.0.3.
Published: 2026-09-14
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch Immediately
AI Analysis

Impact

Prior to version 1.0.3, the /admin/gateways/test endpoint in IBM ContextForge performs DNS resolution during input validation but later performs an unbound look‑up before establishing the transport connection. This Time‑of‑Check to Time‑of‑Use race allows an attacker to supply a DNS name that resolves to a public address during validation and to a private or cloud‑metadata address at connection time, thereby bypassing the SSRF controls that were applied only to the validation result. The result is an internal or cloud‑metadata request originating from the gateway that can steal credentials or probe the internal network.

Affected Systems

IBM ContextForge gateway (mcp-context-forge, mcp-contextforge-gateway) running any version earlier than 1.0.3, when the MCPGATEWAY_ADMIN_API_ENABLED flag is set to true and the attacker can manipulate a database record that grants gateways.read permissions. The vulnerable endpoint resides in mcpgateway/admin.py and uses validate_gateway_test_url() from common/validators.py, with the ResilientHttpClient performing a second resolution.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.6, indicating a medium impact, and an EPSS score of < 1%, suggesting a low likelihood of exploitation. It is not listed in CISA KEV. Likely attack scenarios involve DNS rebinding or injection of malicious gateway entries via a privileged database role, and require network connectivity to the gateway, an enabled admin API, and the ability to alter gateway configurations. Once those prerequisites are met, the race condition enables an attacker to reach internal hosts or metadata services and potentially exfiltrate secrets or further pivot within the host network.

Generated by OpenCVE AI on September 20, 2026 at 23:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade IBM ContextForge to version 1.0.3 or later so that the race condition is fixed.
  • If the admin API is not required for your deployment, disable the MCPGATEWAY_ADMIN_API_ENABLED configuration to remove the exposed endpoint.
  • Revoke the administrative database roles to eliminate the ability to insert malicious gateway entries that could facilitate DNS rebinding.

Generated by OpenCVE AI on September 20, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9hgc-g3w5-67cm ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls validate_gateway_test_url() in mcpgateway/common/validators.py to resolve and reject private, loopback, link-local, and cloud-metadata addresses, but ResilientHttpClient later resolves the original hostname again without binding the validated address. When MCPGATEWAY_ADMIN_API_ENABLED is enabled, an attacker with a database-backed role containing explicit gateways.read permission can use DNS rebinding to return a public address during validation and a private or metadata address during connection, bypassing ssrf_blocked_networks and ssrf_dns_fail_closed because those controls apply only to the validation-time result. The endpoint's allow_admin_bypass=False setting means a bootstrap-only virtual platform-admin identity without a database role is not sufficient. Successful exploitation can reach internal services and cloud metadata, expose cloud credentials, access internal APIs, or probe internal network ports. This issue is fixed in version 1.0.3.
Title ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
Weaknesses CWE-350
CWE-367
CWE-918
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:33:41.529Z

Reserved: 2026-06-10T16:43:31.241Z

Link: CVE-2026-53708

cve-icon Vulnrichment

Updated: 2026-09-14T16:33:32.249Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:11.883

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-53708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-350

    Reliance on Reverse DNS Resolution for a Security-Critical Action

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-918

    Server-Side Request Forgery (SSRF)