PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16637 OPeNDAP Inc. CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T14:16:57.033Z and has not been modified since then. OPeNDAP Hyrax is vulnerable to SSRF and credential disclosure due to unvalidated HTTP redirects that bypass the AllowedHosts allowlist. This allows attackers to leak Earthdata headers (User-Id, Echo-Token) to controlled endpoints. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM. Organizations using OPeNDAP Hyrax should prioritize verifying their inventory for affected versions and applying vendor remediation if available. Limited source detail is available, and defenders should focus on validating redirects, restricting allowed hosts, and monitoring for suspicious activity. The CVE record indicates OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects. Defenders should verify their inventory for affected OPeNDAP Hyrax versions and apply vendor remediation if available.

Vendor
OPeNDAP Inc.
Product
hyrax-docker
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-08-10
Advisory published
2026-08-07
Advisory updated
2026-08-10

Who should care

Organizations using OPeNDAP Hyrax, especially those handling sensitive Earthdata headers, should be aware of this vulnerability and take steps to mitigate it. They should verify their inventory for affected versions, apply vendor remediation if available, and monitor for suspicious activity. Additionally, they should restrict allowed hosts and validate redirects to prevent exploitation.

Technical summary

OPeNDAP Hyrax is vulnerable to SSRF and credential disclosure due to unvalidated HTTP redirects that bypass the AllowedHosts allowlist. This allows attackers to leak Earthdata headers (User-Id, Echo-Token) to controlled endpoints. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM. Organizations using OPeNDAP Hyrax should prioritize verifying their inventory for affected versions and applying vendor remediation if available.

Defensive priority

Organizations using OPeNDAP Hyrax should prioritize verifying their inventory for affected versions and applying vendor remediation if available.

Recommended defensive actions

  • Verify inventory for affected OPeNDAP Hyrax versions
  • Apply vendor remediation if available
  • Monitor for suspicious HTTP redirect activity
  • Restrict allowed hosts and validate redirects
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record indicates OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects. The NVD entry is currently 6.5 MEDIUM. Limited source detail is available. Organizations should verify their inventory for affected OPeNDAP Hyrax versions and apply vendor remediation if available. The vulnerability allows attackers to leak Earthdata headers (User-Id, Echo-Token) to controlled endpoints. Defenders should focus on validating redirects, restricting allowed hosts, and monitoring for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T14:16:57.033Z and has not been modified since then.