DNS Rebinding Vulnerability in ContextForge by IBM
CVE-2026-53708

6.6MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
14 September 2026

What is CVE-2026-53708?

ContextForge, an AI gateway and proxy, harbored a DNS rebinding vulnerability that allows an attacker with specific database roles to bypass access controls. The flaw arises when the '/admin/gateways/test' endpoint fails to properly validate addresses due to the ResilientHttpClient's behavior, which may expose sensitive internal services and cloud metadata. Successful exploitation can lead to the compromise of cloud credentials and access to internal APIs. The issue has been addressed in version 1.0.3.

Affected Version(s)

mcp-context-forge < 1.0.3

mcp-contextforge-gateway < 1.0.3

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.