CVE-2026-16637
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Aug 07, 2026
Vendor
unknown
Description
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.