Beveiligingsadvies
CVE-2026-16637
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.