The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade mcp-contextforge-gateway to version 1.0.3 or higher.
mcp-contextforge-gateway is a ContextForge AI Gateway — an AI gateway, registry, and proxy for MCP, A2A, and REST/gRPC APIs. Exposes a unified control plane with centralized governance, discovery, and observability. Optimizes agent and tool calling, and supports plugins.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) in the /admin/gateways/test endpoint due to a race condition between DNS resolution at validation time and at connection time, allowing DNS rebinding. An attacker can access internal network resources and potentially retrieve sensitive cloud credentials by submitting a crafted URL and manipulating DNS responses between validation and connection. This is only exploitable if the MCPGATEWAY_ADMIN_API_ENABLED configuration is set to true and the attacker possesses a credential with the gateways.read permission assigned via a database role.