Security Advisory

CVE-2026-18905

7.7
HIGH

Vulnerability Description

IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.
Published Date September 4, 2026
Official Source NIST NVD Advisory