CVE-2026-77822

8.2

IBM · ContextForge MCP Gateway

IBM ContextForge MCP Gateway is vulnerable to server-side request forgery via DNS rebinding, which may allow an authenticated attacker to access sensitive information.

Executive summary

A high-severity server-side request forgery vulnerability in IBM ContextForge MCP Gateway allows authenticated attackers to potentially compromise sensitive data.

Vulnerability

This vulnerability is a Server-Side Request Forgery (CWE-918) triggered via DNS rebinding. It requires the attacker to have authenticated access to the system to execute the request.

Business impact

The vulnerability carries a CVSS score of 8.2, reflecting a high risk to data confidentiality and integrity. Successful exploitation could allow an attacker to bypass network controls, potentially exposing internal infrastructure or sensitive configuration data that is otherwise inaccessible from the external network.

Remediation

Immediate Action: Upgrade IBM ContextForge MCP Gateway to version 1.0.9 or later as specified in the official IBM security advisory.

Proactive Monitoring: Monitor server logs for unusual outbound requests or unexpected DNS resolution patterns originating from the gateway service.

Compensating Controls: Implement strict egress filtering on the gateway host to prevent unauthorized outbound connections to internal or sensitive external network segments.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the clear path to remediation, organizations should prioritize updating the ContextForge MCP Gateway to version 1.0.9 immediately. Failure to patch leaves the internal environment vulnerable to information disclosure and potential lateral movement by authenticated actors.

More IBM CVEs

Sources