{"api_version":"v1","generated_at":"2026-10-08T20:15:00+00:00","product":{"cve_count":5,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-ibm-contextforge-mcp-gateway-7d065f41c731","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"ContextForge MCP Gateway","next_cursor":null,"observations":[{"affected":"ContextForge MCP Gateway: 1.0.0 \u2264 1.0.8","affected_versions_present":true,"cve_id":"CVE-2026-77825","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77825","fixed":"IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.8Upgrade to version 1.0.9 or later. See release notes https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.9","last_modified":"2026-09-26T22:51:20.182Z","patch_url":"https://www.ibm.com/support/pages/node/7289314","primary_source":"","published":"2026-09-24T14:21:18.507Z"},{"affected":"ContextForge MCP Gateway: <= v1.0.4","affected_versions_present":true,"cve_id":"CVE-2026-11918","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-11918","fixed":"| Product | Affected Version(s) | Fix Version | Instructions |; |---|---|---|---|; | | <=1.0.4 | 1.0.5 | Upgrade to v1.0.5 or later. . |; IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<=1.0.4; v1.0.5 or later; See [release notes]( https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.5) https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.5%29; Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description>","last_modified":"2026-09-20T00:45:43.821Z","patch_url":"https://www.ibm.com/support/pages/node/7285720","primary_source":"","published":"2026-09-15T17:28:57.954Z"},{"affected":"ContextForge MCP Gateway: 1.0.0 \u2264 1.0.7","affected_versions_present":true,"cve_id":"CVE-2026-78573","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-78573","fixed":"IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.9Upgrade to v1.0.10. See release notes. Additionally, ensure platform_admin_password, default_user_password, and basic_auth_password are set to strong, non-default values before enabling api_allow_basic_auth or mcpgateway_ui_enabled. Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description>","last_modified":"2026-09-11T20:31:29.613Z","patch_url":"https://www.ibm.com/support/pages/node/7286834","primary_source":"","published":"2026-09-10T21:42:36.717Z"},{"affected":"ContextForge MCP Gateway: <= v1.0.7","affected_versions_present":true,"cve_id":"CVE-2026-18486","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-18486","fixed":"IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<=v1.0.7Upgrade to v1.0.8. See [release notes]( https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.8) https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.8%29 . Rotate `JWT_SECRET_KEY`, `AUTH_ENCRYPTION_SECRET`, `DATABASE_URL`, `REDIS_URL`, and `BASIC_AUTH_PASSWORD` on any deployment running prior versions.; Note: From version v1.0.8 on a more complex AUTH_ENCRYPTION_SECRET is required:; Action required before upgrading: run the one-shot re-encryption script (mcpgateway/scripts/migrate_enc_secret.py) with the old and new keys while the gateway is stopped. See the full rotation guide at docs/docs/operations/auth-encryption-secret-rotation.md https://github.com/IBM/mcp-context-forge/blob/v1.0.8/docs/docs/operations/auth-encryption-secret-rotation.md for step-by-step instructions, deployment-specific commands, and special cases (Helm/Kubernetes, Python package consumers, rollback).","last_modified":"2026-09-10T15:07:06.035Z","patch_url":"https://www.ibm.com/support/pages/node/7286052","primary_source":"","published":"2026-09-04T16:24:45.432Z"},{"affected":"ContextForge MCP Gateway: <= v1.0.8","affected_versions_present":true,"cve_id":"CVE-2026-77822","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77822","fixed":"IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<= v1.0.8Upgrade to v1.0.9; https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.9; Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description>","last_modified":"2026-09-04T18:24:58.315Z","patch_url":"https://www.ibm.com/support/pages/node/7286055","primary_source":"","published":"2026-09-04T15:15:35.403Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"IBM"}}
