Beveiligingsadvies

CVE-2026-16637

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-07 13:14:10
Laatst bijgewerkt 2026-08-10 11:57:04
Toegewezen door certcc
CVSS-score 6.5
Status PUBLISHED

Beschrijving

OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.