{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anasaearthdata-search1.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nasa:earthdata-search:1.0.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82801"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["earthdata-search (1.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["NASA"],"content_html":"\u003cp\u003eNASA earthdata-search version 1.0.0 contains a Server-Side Request Forgery (SSRF) vulnerability. The flaw exists within the scaleImage function located in the file serverless/src/scaleImage/handler.js, which is part of the application's scale Endpoint component. This vulnerability allows an unauthenticated remote attacker to manipulate inputs to the function, forcing the server to perform unauthorized HTTP requests to arbitrary destinations. This could potentially be leveraged to access internal metadata services, cloud infrastructure resources, or internal network services not intended for public access. The vulnerability is publicly disclosed, and no official patch has been provided by the vendor, as they did not respond to initial disclosure efforts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies the publicly accessible scale Endpoint in the NASA earthdata-search application.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request targeting the scaleImage handler function.\u003c/li\u003e\n\u003cli\u003eAttacker injects a target URL into the input parameter processed by the scaleImage function.\u003c/li\u003e\n\u003cli\u003eThe server-side application fails to validate or sanitize the attacker-provided URL.\u003c/li\u003e\n\u003cli\u003eThe application performs a backend HTTP GET or POST request to the attacker-specified target.\u003c/li\u003e\n\u003cli\u003eAttacker observes the response or network impact to exfiltrate data or probe internal network architecture.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows remote attackers to bypass network perimeters, potentially leading to the unauthorized disclosure of internal data, sensitive information from internal cloud metadata services, or the ability to interact with other internal-only API endpoints within the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of internet-facing instances of NASA earthdata-search 1.0.0 within the environment. If the software is deployed, implement egress filtering at the network level to prevent the server from reaching internal resources or unauthorized external domains. Monitor web server logs for suspicious requests containing URL parameters that deviate from expected patterns within the scaleImage handler endpoint.\u003c/p\u003e\n","date_modified":"2026-08-31T15:58:28Z","date_published":"2026-08-31T15:58:28Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nasa-ssrf/","summary":"NASA earthdata-search version 1.0.0 contains a Server-Side Request Forgery (SSRF) vulnerability in the scaleImage function, allowing remote attackers to perform unauthorized requests.","title":"SSRF Vulnerability in NASA earthdata-search","url":"https://feed.craftedsignal.io/briefs/2026-08-nasa-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nasa:earthdata-Search:1.0.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}