Description
oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, the @orpc/server CORS plugin in packages/server/src/plugins/cors.ts copies a client's incoming Vary request header into the response instead of controlling Vary as a response-only header and using Origin for request-origin variation. In deployments behind a shared cache, CDN, or reverse proxy that keys responses using Vary, a client can inject arbitrary variation values, pollute cache keys, and cause inconsistent CORS enforcement for other clients. Default non-cached configurations have no established direct confidentiality, integrity, or availability impact. This issue is fixed in version 1.14.8.
Published: 2026-09-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cache or CORS Bypass via Header Injection
Action: Upgrade
AI Analysis

Impact

A client can inject arbitrary values into the Vary request header. The oRPC @orpc/server CORS plugin copies this header unchanged into the response, allowing the attacker to manipulate the cache key used by shared caches, CDNs, or reverse proxies. This results in cache pollution and inconsistent enforcement of CORS policies for subsequent requests. While the vulnerability does not grant direct confidentiality, integrity, or availability damage, it undermines the intended request‑origin isolation of the CORS mechanism.

Affected Systems

The flaw exists in the @orpc/server CORS plugin of the oRPC framework from the vendor middleapi. Versions released prior to v1.14.8 are affected. Deployments that rely on shared caching layers, CDN edge servers, or reverse proxies that key responses based on the Vary header are explicitly vulnerable when they accept requests from untrusted clients.

Risk and Exploitability

The CVSS score of 6.3 reflects moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the current threat landscape, and the vulnerability is not cataloged in CISA KEV. An attacker only needs to send standard HTTP requests containing a malicious Vary header; no authentication or elevated privileges are required. The primary risk arises from cache key manipulation and accidental relaxation of CORS restrictions for other tenants.

Generated by OpenCVE AI on September 17, 2026 at 22:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official fix by upgrading @orpc/server to v1.14.8 or later
  • Configure the server to generate the Vary header internally and reject or sanitize any Vary header received from clients
  • Configure caching proxies or CDN edge servers to strip client‑supplied Vary headers before forwarding them to downstream services

Generated by OpenCVE AI on September 17, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j9v4-rhgr-4m5f oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Middleapi
Middleapi orpc
Vendors & Products Middleapi
Middleapi orpc

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, the @orpc/server CORS plugin in packages/server/src/plugins/cors.ts copies a client's incoming Vary request header into the response instead of controlling Vary as a response-only header and using Origin for request-origin variation. In deployments behind a shared cache, CDN, or reverse proxy that keys responses using Vary, a client can inject arbitrary variation values, pollute cache keys, and cause inconsistent CORS enforcement for other clients. Default non-cached configurations have no established direct confidentiality, integrity, or availability impact. This issue is fixed in version 1.14.8.
Title oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
Weaknesses CWE-113
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T19:40:51.991Z

Reserved: 2026-08-20T19:28:35.245Z

Link: CVE-2026-77360

cve-icon Vulnrichment

Updated: 2026-09-16T19:40:43.092Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:17:38.020

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-77360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:01Z

Weaknesses
  • CWE-113

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')