CVE-2026-18905: IBM ContextForge MCP Gateway is affected by server-side request forgery via DNS TOCTOU at tool invocation
IBM ContextForge MCP Gateway (mcp-contextforge-gateway) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mcp-contextforge-gatewayto a version that resolves this vulnerability.Fixed in 1.0.6Patch pull/5925 - Compensating control
Mitigate the DNS rebinding/SSRF risk at tool invocation by preventing DNS rebinding-style behavior (e.g., block or restrict outbound DNS/HTTP calls to attacker-controlled domains) until the referenced fix is applied.
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to the MCP ContextForge MCP Gateway. No user interaction is required, and the attack can be performed over the network.
Which deployments should be considered affected?
IBM ContextForge MCP Gateway, identified as mcp-contextforge-gateway, is affected through version 1.0.6. The provided information does not state whether any particular default configuration is required.
What is the impact of successful exploitation?
Successful exploitation may allow an authenticated attacker to obtain sensitive information through server-side request forgery using DNS rebinding during tool invocation.