OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.Referenceshttps://github.com/OPENDAP/hyrax-dockerhttps://www.opendap.org/official-hyrax-1-18-release/