CVE-2026-16637
ANALYSIS PENDINGOPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects
Title source: cnaDescription
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
References (3)
Core 3
Core References
Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/305509
Scores
EPSS
0.0021
EPSS Percentile
11.0%
Details
Status
published
Products (1)
OPeNDAP Inc./hyrax-docker
1.18.0
Published
Aug 07, 2026
Tracked Since
Aug 07, 2026