Impact
A client can inject arbitrary values into the Vary request header. The oRPC @orpc/server CORS plugin copies this header unchanged into the response, allowing the attacker to manipulate the cache key used by shared caches, CDNs, or reverse proxies. This results in cache pollution and inconsistent enforcement of CORS policies for subsequent requests. While the vulnerability does not grant direct confidentiality, integrity, or availability damage, it undermines the intended request‑origin isolation of the CORS mechanism.
Affected Systems
The flaw exists in the @orpc/server CORS plugin of the oRPC framework from the vendor middleapi. Versions released prior to v1.14.8 are affected. Deployments that rely on shared caching layers, CDN edge servers, or reverse proxies that key responses based on the Vary header are explicitly vulnerable when they accept requests from untrusted clients.
Risk and Exploitability
The CVSS score of 6.3 reflects moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the current threat landscape, and the vulnerability is not cataloged in CISA KEV. An attacker only needs to send standard HTTP requests containing a malicious Vary header; no authentication or elevated privileges are required. The primary risk arises from cache key manipulation and accidental relaxation of CORS restrictions for other tenants.
OpenCVE Enrichment
Github GHSA