{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/305509#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nA vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, the vulnerability may also result in the unintended disclosure of user authentication tokens to unauthorized destinations.\r\n\r\n### Description\r\n**CVE-2026-16637**\r\nOPeNDAP Hyrax is vulnerable to Server Side Request Forgery (SSRF) and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.\r\n\r\nOPeNDAP Hyrax is an open-source data server software that enables remote access to scientific datasets over the internet using the OPeNDAP protocol. It allows users to query, subset, and retrieve data in various formats (such as NetCDF, HDF, or GrADS) without downloading entire files. OPeNDAP Hyrax uses a list of allowed hosts, specified through a regular expression, to limit where it can fetch data. When a requested server responds with a redirect, HTTP 3xx, the software follows the redirect without checking whether the new destination is still on the allowed list. This behavior enables an attacker to redirect the system to an untrusted or internal target that would otherwise be blocked. Additionally, when the system follows such a redirect, it may carry certain user identification headers, including a legacy credential called Echo-Token, to the new destination, even though the main authorization token is correctly stripped by the underlying library.\r\n\r\n### Impact\r\nSuccessful exploitation could allow an unauthenticated remote attacker to access internal services that are not intended to be reachable from the internet. If a user is authenticated when exploitation occurs, the attacker may also obtain the user's Earthdata identifier and a reusable legacy credential. These credentials could be used to access protected datasets or other resources as the affected user.\r\n\r\n### Solution\r\nThe CERT/CC is currently unaware of a practical solution to this problem. OPeNDAP has been notified and is working to develop a patch that will be released shortly, if it hasn't already. Administrator of Hyrax server are advised to review their allowed host configurations carefully and consider limiting exposure of the gateway endpoint to trusted networks until the fix is available, likely in versions Hyrax-1.18.0 or later.\r\n\r\n### Acknowledgements\r\nThanks to the Juan Salvador Sleibe for reporting this issue. This AI-assisted document was written by Timur Snoke.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"},{"category":"other","text":"Changed from Unknown to Affected because OPeNDAP has been notified and is working to develop a patch that will be released shortly, if it hasn't already.","title":"CERT/CC comment on OPeNDAP Inc. notes"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/305509"},{"url":"https://github.com/OPENDAP/hyrax-docker","summary":"https://github.com/OPENDAP/hyrax-docker"}],"title":"OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure","tracking":{"current_release_date":"2026-07-29T15:18:13+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.43"}},"id":"VU#305509","initial_release_date":"2026-07-29 15:18:13.442868+00:00","revision_history":[{"date":"2026-07-29T15:18:13+00:00","number":"1.20260729151813.1","summary":"Released on 2026-07-29T15:18:13+00:00"}],"status":"final","version":"1.20260729151813.1"}},"vulnerabilities":[{"title":"OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.","notes":[{"category":"summary","text":"OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints."}],"cve":"CVE-2026-16637","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#305509"}],"product_status":{"known_affected":["CSAFPID-2486bf06-8b9d-11f1-85eb-123eceb31d7b"]}}],"product_tree":{"branches":[{"category":"vendor","name":"OPeNDAP Inc.","product":{"name":"OPeNDAP Inc. Products","product_id":"CSAFPID-2486bf06-8b9d-11f1-85eb-123eceb31d7b"}}]}}