CVE-2026-16637
EUVD-2026-5447907.08.2026, 14:16
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.