CVE-2026-11918: IBM Contextforge Mcp Gateway

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

Affected products

  • IBM Contextforge Mcp Gateway: up to and including v1.0.4

Published 2026-09-15. Last modified 2026-09-20.