What is CVE-2026-16637?
CVE-2026-16637: A vulnerability in OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist, leaking sensitive Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints. Users should restrict redirects until a patch is applied.
Azərbaycanca: CVE-2026-16637: OPeNDAP Hyrax proqramında aşkar edilmiş boşluqdur. Təsdiqlənməmiş HTTP yönləndirmələri vasitəsilə AllowedHosts icazə siyahısını keçərək SSRF (Server-Side Request Forgery) və Earthdata başlıqlarının (User-Id, Echo-Token) sızmasına səbəb olur. İstifadəçilərə yamaq tətbiq edənə qədər HTTP yönləndirmələrini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What product is affected by CVE-2026-16637?
CVE-2026-16637 affects the OPeNDAP Hyrax software.
Which sensitive headers can be leaked due to CVE-2026-16637?
This vulnerability can lead to the leakage of Earthdata headers, including User-Id and Echo-Token.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.