Server-Side Request Forgery in NASA Earthdata-Search
CVE-2026-82801
Key Information:
- Vendor
Nasa
- Status
- Vendor
- CVE Published:
- 31 August 2026
Badges
What is CVE-2026-82801?
A vulnerability exists in the scaleImage function within the serverless/src/scaleImage/handler.js file of NASA's Earthdata-Search product version 1.0.0. This flaw allows a remote attacker to exploit the scale Endpoint, potentially leading to unauthorized server-side request forgery (SSRF). The exploit enables manipulation of server requests, which could facilitate access to sensitive internal resources. Despite attempts to inform the vendor, there has been no response regarding this security issue.
Affected Version(s)
earthdata-search 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
