CVE-2026-82801
NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-918 |
| Vendor | nasa |
| Product | earthdata-search |
| Published | Aug 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for nasa earthdata-search
Be the first to know when new high vulnerabilities affecting nasa earthdata-search are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
NASA / earthdata-search
1.0.0
References
vuldb.com: https://vuldb.com/vuln/397222 vuldb.com: https://vuldb.com/vuln/397222/cti vuldb.com: https://vuldb.com/cve/CVE-2026-82801 vuldb.com: https://vuldb.com/submit/881731 github.com: https://github.com/natanmorette-thoropass/thoropass-vuln-research-program/tree/main/2026/Unauthenticated%20Scale%20Image%20SSRF
Credits
๐ nmmorette (VulDB User) VulDB CNA Team