Unvalidated HTTP Redirects in OPeNDAP Hyrax Exposing Sensitive User Information
CVE-2026-16637
Currently unrated
What is CVE-2026-16637?
The OPeNDAP Hyrax product is vulnerable to Server-Side Request Forgery (SSRF) and credential disclosure through unvalidated HTTP redirects. This flaw allows attackers to bypass the AllowedHosts allowlist and gain unauthorized access to sensitive Earthdata headers, including User-Id and Echo-Token. This exposure can lead to significant security risks, as malicious actors might exploit this vulnerability to send crafted requests to arbitrary endpoints, compromising user data integrity and privacy.
Affected Version(s)
hyrax-docker 1.18.0
