CVE-2026-16637
Description
AI Translation Available
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
https://www.kb.cert.org/vuls/id/305509
https://github.com/OPENDAP/hyrax-docker
https://www.opendap.org/official-hyrax-1-18-release/