Vibe Coding
Four IBM ContextForge MCP Gateway CVEs land the same day, two of them DNS rebinding
Published 2026-09-04: CVE-2026-18905 (<= v1.0.6, DNS rebinding during tool invocation) and CVE-2026-77822 (SSRF via DNS rebinding) both defeat URL validation by re-resolving between check and connect; CVE-2026-18486 (<= v1.0.7) leaks credentials and escalates privileges through improper jq filter validation; CVE-2026-18489 (<= 1.0.8, Translate utility) exposes one session's data to another. An MCP gateway is a deliberate SSRF machine, so validate-then-fetch without pinning the resolved IP is not a guard.
Source
↳ Follow the thread