VYPR

hyrax-docker

by Opendap

CVEs (1)

  • CVE-2026-16637MedAug 7, 2026
    risk 0.42cvss 6.5epss 0.00

    OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.