CVE-2026-16637

Published: Ago 07, 2026 Last Modified: Ago 07, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

https://www.kb.cert.org/vuls/id/305509
https://github.com/OPENDAP/hyrax-docker
https://www.opendap.org/official-hyrax-1-18-release/