๐Ÿ” CVE Alert

CVE-2026-77360

UNKNOWN 0.0

oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, the @orpc/server CORS plugin in packages/server/src/plugins/cors.ts copies a client's incoming Vary request header into the response instead of controlling Vary as a response-only header and using Origin for request-origin variation. In deployments behind a shared cache, CDN, or reverse proxy that keys responses using Vary, a client can inject arbitrary variation values, pollute cache keys, and cause inconsistent CORS enforcement for other clients. Default non-cached configurations have no established direct confidentiality, integrity, or availability impact. This issue is fixed in version 1.14.8.

CWE CWE-113
Vendor middleapi
Product orpc
Published Sep 16, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for middleapi orpc

Be the first to know when new unknown vulnerabilities affecting middleapi orpc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

middleapi / orpc
< 1.14.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/middleapi/orpc/security/advisories/GHSA-j9v4-rhgr-4m5f github.com: https://github.com/middleapi/orpc/issues/1661 github.com: https://github.com/middleapi/orpc/pull/1662 github.com: https://github.com/middleapi/orpc/commit/daabded122a89d323357c4c401e879701864cb2f github.com: https://github.com/middleapi/orpc/releases/tag/v1.14.8