PT-2026-93900 · Orpc · Orpc

CVE-2026-77360

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions oRPC versions prior to 1.14.8
Description The CORS plugin in the @orpc/server package, specifically within packages/server/src/plugins/cors.ts, incorrectly copies the Vary request header from the client directly into the response. The Vary header is intended to be a response-only header that informs downstream caches and proxies how to key cached responses. By injecting arbitrary values into this header, a client can pollute cache keys in environments using a shared cache, CDN, or reverse proxy. This can lead to inconsistent CORS enforcement for other clients. In default configurations without caching, there is no direct impact on confidentiality, integrity, or availability.
Recommendations Update @orpc/server and any other @orpc/* packages bundling the CORS plugin to version 1.14.8.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77360
GHSA-J9V4-RHGR-4M5F

Affected Products

Orpc