CVE-2026-82802 | NASA earthdata-search 1.0.0 granules Endpoint handler.js OpenSearchGranuleSearchLambda openSearchOsdd server-side request forgery
A vulnerability classified as problematic was found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd can lead to server-side request forgery.
This vulnerability is tracked as CVE-2026-82802. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More