Vulnerability Description
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
References
- https://github.com/OPENDAP/hyrax-docker
- https://www.opendap.org/official-hyrax-1-18-release/
- https://www.kb.cert.org/vuls/id/305509
FAQ
What is CVE-2026-16637?
CVE-2026-16637 is a documented vulnerability. OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoi...
How severe is CVE-2026-16637?
CVSS scoring is not yet available for CVE-2026-16637. Check NVD for updates.
Is there a patch for CVE-2026-16637?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.