SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18905

HIGH · CVSS 7.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM ContextForge MCP Gateway versions up to 1.0.6 are vulnerable to a DNS rebinding attack, which could enable remote authenticated attackers to access sensitive information during tool invocation. Organizations using this gateway should prioritize patching to mitigate the risk of data exposure. Immediate action is recommended for those handling sensitive data or operating in regulated environments.

CVE
CVE-2026-18905
Severity
HIGH
CVSS
7.7
EPSS
0.34%

Original NVD Description

IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)