A server-side request forgery (SSRF) vulnerability has been identified in NASA earthdata-search version 1.0.0. The vulnerability exists in the scaleImage function within the file serverless/src/scaleImage/handler.js at the scale Endpoint component. An attacker can exploit this vulnerability remotely by manipulating inputs to the affected function, potentially causing the server to make unintended requests to internal or external resources. A public exploit is available, increasing the risk of active exploitation. The vulnerability was responsibly disclosed to the vendor, but no response was received. The issue carries a high criticality rating given the public exploit availability and the potential for abuse in a government-affiliated application handling geospatial and earth science data.