CVE-2026-16637

Summary

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

Affected Software

VendorProductVersion RangeStatus
OPeNDAP Inc.hyrax-docker1.18.0affected

Weaknesses

  • CWE-918 Server-Side Request Forgery (SSRF)
  • CWE-201Exposure of Sensitive Information Through Shared Resources

ADP Enrichment

CVE Program Container

Additional References

References