PT-2026-83864 · Nasa · Earthdata-Search

·

CVE-2026-82801

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NASA earthdata-search version 1.0.0
Description A server-side request forgery (SSRF) exists in the scale Endpoint component. This issue occurs within the scaleImage() function located in the serverless/src/scaleImage/handler.js file. A remote attacker can initiate a manipulation to trigger the flaw.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the scaleImage() function to minimize the risk of exploitation.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82801

Affected Products

Earthdata-Search