Impact
The vulnerability in IBM ContextForge MCP Gateway allows a remotely authenticated attacker to trigger server‑side request forgery through DNS rebinding on the A2A agent invocation endpoint. By manipulating DNS resolution, the gateway can be coerced into making requests to internal or protected resources and thereby disclose sensitive information, illustrating a classic SSRF flaw (CWE‑918).
Affected Systems
Affected is IBM ContextForge MCP Gateway version 1.0.8 or earlier. IBM recommends upgrading to v1.0.9 to remove the flaw from all deployments that expose the A2A subsystem.
Risk and Exploitability
The CVSS score of 8.2 reflects high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation yet. Exploitation still requires remote authenticated access, so attackers with gateway credentials could abuse it by crafting DNS‑rebinding requests that resolve to internal targets. The risk is significant for environments exposing the A2A service without appropriate network controls.
OpenCVE Enrichment