MEDIUM
OPeNDAP Inc.
CVE published 2026-08-07
CVE-2026-16637
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T14:16:57.033Z and has not been modified since then. OPeNDAP Hyrax is vulnerable to SSRF and credential disclosure due to unvalidated HTTP redirects that bypass the AllowedHosts allowlist. This allows attackers to leak Earthdata headers (User-Id, Echo-Token) to controlled endpoints. The vulnerabil [truncated]