PatchSiren

OPeNDAP Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OPeNDAP Inc. CVE published 2026-08-07

CVE-2026-16637

CVE-2026-16637 debrief based on the supplied source corpus. OPeNDAP Hyrax is affected by a vulnerability that allows Server-Side Request Forgery (SSRF) and credential disclosure due to unvalidated HTTP redirects. These redirects bypass the AllowedHosts allowlist and leak Earthdata headers, including User-Id and Echo-Token, to attacker-controlled endpoints. Defenders responsible for OPeNDAP Hyrax deploymen [truncated]