Product
IBM ContextForge MCP Gateway versions 1.0.6 and earlier contain a DNS rebinding vulnerability that allows remote authenticated attackers to access sensitive information during tool invocation.