VYPR

hyrax-docker

by Opendap

CVEs (1)

  • CVE-2026-16637Aug 7, 2026
    risk 0.00cvss epss

    OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.