DNS Rebinding Vulnerability in ContextForge by IBM
CVE-2026-53708
6.6MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 14 September 2026
What is CVE-2026-53708?
ContextForge, an AI gateway and proxy, harbored a DNS rebinding vulnerability that allows an attacker with specific database roles to bypass access controls. The flaw arises when the '/admin/gateways/test' endpoint fails to properly validate addresses due to the ResilientHttpClient's behavior, which may expose sensitive internal services and cloud metadata. Successful exploitation can lead to the compromise of cloud credentials and access to internal APIs. The issue has been addressed in version 1.0.3.
Affected Version(s)
mcp-context-forge < 1.0.3
mcp-contextforge-gateway < 1.0.3