CVE-2026-16637

ANALYSIS PENDING

OPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects

Title source: cna
STIX 2.1

Description

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

References (3)

Core 3

Scores

EPSS 0.0021
EPSS Percentile 11.0%

Details

Status published
Products (1)
OPeNDAP Inc./hyrax-docker 1.18.0
Published Aug 07, 2026
Tracked Since Aug 07, 2026