PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16637 OPeNDAP Inc. CVE debrief

CVE-2026-16637 debrief based on the supplied source corpus. OPeNDAP Hyrax is affected by a vulnerability that allows Server-Side Request Forgery (SSRF) and credential disclosure due to unvalidated HTTP redirects. These redirects bypass the AllowedHosts allowlist and leak Earthdata headers, including User-Id and Echo-Token, to attacker-controlled endpoints. Defenders responsible for OPeNDAP Hyrax deployments should assess their exposure and prioritize mitigation efforts. The vulnerability's impact is currently limited by the lack of detailed information on exploitation and affected versions, but it has the potential for significant operational impacts if exploited.

Vendor
OPeNDAP Inc.
Product
hyrax-docker
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-09-08
Advisory published
2026-08-07
Advisory updated
2026-09-08

Who should care

Defenders responsible for OPeNDAP Hyrax deployments, vulnerability management teams, security teams, and operators of affected systems should assess their exposure and prioritize mitigation efforts. These stakeholders should review and update the AllowedHosts allowlist, monitor for potential SSRF and credential disclosure attacks, and implement compensating controls for exposed systems. Additionally, they should track and document remediation efforts to确保

Why it matters

CVE-2026-16637 allows SSRF and credential disclosure in OPeNDAP Hyrax deployments due to unvalidated HTTP redirects. Defenders should prioritize verifying and mitigating this vulnerability, especially those responsible for OPeNDAP Hyrax deployments. The vulnerability's impact is currently limited by the lack of detailed information on exploitation and affected versions.

  • Potential SSRF attacks against OPeNDAP Hyrax deployments
  • Possible credential disclosure to attacker-controlled endpoints
  • Need to verify and mitigate unvalidated HTTP redirects
  • Importance of reviewing and updating the AllowedHosts allowlist

Technical summary

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Defenders should prioritize verifying and mitigating unvalidated HTTP redirects in OPeNDAP Hyrax deployments to prevent potential SSRF attacks and credential disclosure. The vulnerability's technical impact is significant, but its current operational impact is limited by the lack of detailed information on exploitation and affected versions.

Defensive priority

Defenders should prioritize verifying and mitigating unvalidated HTTP redirects in OPeNDAP Hyrax deployments.

Recommended defensive actions

  • Verify and mitigate unvalidated HTTP redirects in OPeNDAP Hyrax deployments
  • Review and update the AllowedHosts allowlist
  • Monitor for potential SSRF and credential disclosure attacks
  • Perform vulnerability scanning to identify potentially affected systems
  • Implement compensating controls for exposed systems
  • Review and update incident response plans to account for potential exploitation
  • Track and document remediation efforts

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score of 6.5. The vulnerability allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints. There is no information on known or unknown affected scope, but defenders should verify and mitigate unvalidated HTTP redirects in OPeNDAP Hyrax deployments. The CVE record was published on 2026-08-07T14:16:57.033Z.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16637 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16637

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16637 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16637

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.