CVE-2026-16637 PUBLISHED

OPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects

Assigner: certcc
Reserved: 22.07.2026 Published: 07.08.2026 Updated: 07.08.2026

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

Product Status

Vendor OPeNDAP Inc.
Product hyrax-docker
Versions
  • Version 1.18.0 is affected

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF)
  • CWE-201Exposure of Sensitive Information Through Shared Resources