MEDIUM
OPeNDAP Inc.
CVE published 2026-08-07
CVE-2026-16637
CVE-2026-16637 debrief based on the supplied source corpus. OPeNDAP Hyrax is affected by a vulnerability that allows Server-Side Request Forgery (SSRF) and credential disclosure due to unvalidated HTTP redirects. These redirects bypass the AllowedHosts allowlist and leak Earthdata headers, including User-Id and Echo-Token, to attacker-controlled endpoints. Defenders responsible for OPeNDAP Hyrax deploymen [truncated]