PT-2026-93900 · Orpc · Orpc
CVE-2026-77360
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
oRPC versions prior to 1.14.8
Description
The CORS plugin in the
@orpc/server package, specifically within packages/server/src/plugins/cors.ts, incorrectly copies the Vary request header from the client directly into the response. The Vary header is intended to be a response-only header that informs downstream caches and proxies how to key cached responses. By injecting arbitrary values into this header, a client can pollute cache keys in environments using a shared cache, CDN, or reverse proxy. This can lead to inconsistent CORS enforcement for other clients. In default configurations without caching, there is no direct impact on confidentiality, integrity, or availability.Recommendations
Update
@orpc/server and any other @orpc/* packages bundling the CORS plugin to version 1.14.8.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orpc