CVE-2026-77822: IBM ContextForge MCP Gateway is affected by server-side request forgery (DNS rebinding) via the A2A agent invocation endpoint
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
Other sources
MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ContextForge MCP Gatewayto a version that resolves this vulnerability.Fixed in v1.0.9
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be remotely authenticated. No user interaction is required, but the attack complexity is rated high.
What is the primary impact?
Successful exploitation can allow an authenticated remote attacker to obtain sensitive information through server-side request forgery using DNS rebinding.
Which component should be prioritized for remediation?
Prioritize IBM ContextForge MCP Gateway instances, specifically the A2A agent invocation endpoint identified as the affected attack path.