PatchSiren cyber security CVE debrief
CVE-2026-16637 OPeNDAP Inc. CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T14:16:57.033Z and has not been modified since then. OPeNDAP Hyrax is vulnerable to SSRF and credential disclosure due to unvalidated HTTP redirects that bypass the AllowedHosts allowlist. This allows attackers to leak Earthdata headers (User-Id, Echo-Token) to controlled endpoints. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM. Organizations using OPeNDAP Hyrax should prioritize verifying their inventory for affected versions and applying vendor remediation if available. Limited source detail is available, and defenders should focus on validating redirects, restricting allowed hosts, and monitoring for suspicious activity. The CVE record indicates OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects. Defenders should verify their inventory for affected OPeNDAP Hyrax versions and apply vendor remediation if available.
- Vendor
- OPeNDAP Inc.
- Product
- hyrax-docker
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-08-10
Who should care
Organizations using OPeNDAP Hyrax, especially those handling sensitive Earthdata headers, should be aware of this vulnerability and take steps to mitigate it. They should verify their inventory for affected versions, apply vendor remediation if available, and monitor for suspicious activity. Additionally, they should restrict allowed hosts and validate redirects to prevent exploitation.
Technical summary
OPeNDAP Hyrax is vulnerable to SSRF and credential disclosure due to unvalidated HTTP redirects that bypass the AllowedHosts allowlist. This allows attackers to leak Earthdata headers (User-Id, Echo-Token) to controlled endpoints. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM. Organizations using OPeNDAP Hyrax should prioritize verifying their inventory for affected versions and applying vendor remediation if available.
Defensive priority
Organizations using OPeNDAP Hyrax should prioritize verifying their inventory for affected versions and applying vendor remediation if available.
Recommended defensive actions
- Verify inventory for affected OPeNDAP Hyrax versions
- Apply vendor remediation if available
- Monitor for suspicious HTTP redirect activity
- Restrict allowed hosts and validate redirects
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record indicates OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects. The NVD entry is currently 6.5 MEDIUM. Limited source detail is available. Organizations should verify their inventory for affected OPeNDAP Hyrax versions and apply vendor remediation if available. The vulnerability allows attackers to leak Earthdata headers (User-Id, Echo-Token) to controlled endpoints. Defenders should focus on validating redirects, restricting allowed hosts, and monitoring for suspicious activity.
Official resources
-
CVE-2026-16637 CVE record
CVE.org
-
CVE-2026-16637 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
- Source reference
-
Source reference
af854a3a-2127-422b-91ae-364da2661108
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T14:16:57.033Z and has not been modified since then.