VORANT. Threat Intelligence Sign in Get the full feed

OPeNDAP Hyrax SSRF Leaks Earthdata Tokens

medium vulnerability educationtechnology

A flaw in OPeNDAP Hyrax lets attackers bypass host allowlists via HTTP redirects, enabling SSRF and leaking Earthdata authentication headers.

CERT/CC disclosed CVE-2026-16637, a server-side request forgery vulnerability in OPeNDAP Hyrax, an open-source data server widely used for scientific dataset access via the OPeNDAP protocol. The flaw stems from Hyrax's failure to re-validate HTTP redirect (3xx) destinations against its configured AllowedHosts allowlist, allowing a remote attacker to redirect requests to internal or otherwise restricted systems that should not be reachable from the internet.

Compounding the SSRF issue, when the redirect is followed, Hyrax may forward legacy Earthdata identification headers—specifically User-Id and the reusable Echo-Token—to the attacker-controlled destination, even though the primary authorization token is correctly stripped. An unauthenticated attacker could leverage this to probe internal network services, and if a legitimate authenticated user's session is exploited, the attacker could harvest the user's Earthdata identifier and legacy token to impersonate them and access protected scientific datasets.

No patch is currently available; OPeNDAP has been notified and is developing a fix expected in Hyrax 1.18.0 or later. CERT/CC recommends administrators review AllowedHosts configurations and restrict exposure of the gateway endpoint to trusted networks as an interim mitigation. There is no indication of active exploitation in the wild.

Mentioned in this report

Vulnerabilities CVE-2026-16637

Source reporting: https://kb.cert.org/vuls/id/305509

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free