CVE-2026-16637
N/A
N/A
Summary
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OPeNDAP Inc. | hyrax-docker | 1.18.0 | affected |
Weaknesses
- CWE-918 Server-Side Request Forgery (SSRF)
- CWE-201Exposure of Sensitive Information Through Shared Resources
ADP Enrichment
CVE Program Container
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.