Loading market data...
← Back to CVE feed

CVE-2026-16637

UNKNOWN View on NVD ↗

Description

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.

Published: Aug 07, 2026 14:16 UTC Modified: Aug 07, 2026 14:16 UTC