AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16637

MEDIUM · CVSS 6.5 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

OPeNDAP Hyrax is vulnerable to server-side request forgery (SSRF) and credential disclosure due to unvalidated HTTP redirects that circumvent the AllowedHosts allowlist. This flaw allows attackers to access sensitive Earthdata headers, including User-Id and Echo-Token, by redirecting requests to malicious endpoints. Organizations utilizing OPeNDAP Hyrax should prioritize remediation to protect against potential data leaks and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16637
Severity
MEDIUM
CVSS
6.5
EPSS
0.46%

Original NVD Description

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.