IBM
ContextForge MCP Gateway
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-77825 | 24 Sep 2026 | ContextForge MCP Gateway: 1.0.0 ≤ 1.0.8 | IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.8Upgrade to version 1.0.9 or later. See release notes https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.9 | Update reference ↗ |
| CVE-2026-11918 | 15 Sep 2026 | ContextForge MCP Gateway: <= v1.0.4 | | Product | Affected Version(s) | Fix Version | Instructions |; |---|---|---|---|; | | <=1.0.4 | 1.0.5 | Upgrade to v1.0.5 or later. . |; IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<=1.0.4; v1.0.5 or later; See [release notes]( https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.5) https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.5%29; Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description> | Update reference ↗ |
| CVE-2026-78573 | 10 Sep 2026 | ContextForge MCP Gateway: 1.0.0 ≤ 1.0.7 | IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gatewayv1.0.0 - v1.0.9Upgrade to v1.0.10. See release notes. Additionally, ensure platform_admin_password, default_user_password, and basic_auth_password are set to strong, non-default values before enabling api_allow_basic_auth or mcpgateway_ui_enabled. Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description> | Update reference ↗ |
| CVE-2026-18486 | 4 Sep 2026 | ContextForge MCP Gateway: <= v1.0.7 | IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<=v1.0.7Upgrade to v1.0.8. See [release notes]( https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.8) https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.8%29 . Rotate `JWT_SECRET_KEY`, `AUTH_ENCRYPTION_SECRET`, `DATABASE_URL`, `REDIS_URL`, and `BASIC_AUTH_PASSWORD` on any deployment running prior versions.; Note: From version v1.0.8 on a more complex AUTH_ENCRYPTION_SECRET is required:; Action required before upgrading: run the one-shot re-encryption script (mcpgateway/scripts/migrate_enc_secret.py) with the old and new keys while the gateway is stopped. See the full rotation guide at docs/docs/operations/auth-encryption-secret-rotation.md https://github.com/IBM/mcp-context-forge/blob/v1.0.8/docs/docs/operations/auth-encryption-secret-rotation.md for step-by-step instructions, deployment-specific commands, and special cases (Helm/Kubernetes, Python package consumers, rollback). | Update reference ↗ |
| CVE-2026-77822 | 4 Sep 2026 | ContextForge MCP Gateway: <= v1.0.8 | IBM strongly recommends addressing the vulnerability now.; Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM ContextForge MCP Gateway<= v1.0.8Upgrade to v1.0.9; https://github.com/IBM/mcp-context-forge/releases/tag/v1.0.9; Note: <Component A / B names> are bundled with <Product profile name> to provide <feature / function description> | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.