NONE · 0

CVE-2026-16637

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoi...

Vulnerability Description

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

References

FAQ

What is CVE-2026-16637?

CVE-2026-16637 is a documented vulnerability. OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoi...

How severe is CVE-2026-16637?

CVSS scoring is not yet available for CVE-2026-16637. Check NVD for updates.

Is there a patch for CVE-2026-16637?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.