CVE-2026-82801: NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery
A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attack can be initiated remotely and requires no privileges or user interaction, as reflected by the AV:N/AC:L/PR:N/UI:N vector.
How should this issue be prioritized?
Prioritize it as high severity. A public exploit is available, and successful exploitation can affect confidentiality, integrity, and availability at low impact levels.
Which component should be reviewed for exposure?
The affected component is the scale endpoint, specifically the scaleImage function in serverless/src/scaleImage/handler.js in earthdata-search 1.0.0.