Back

MEDIUM

oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass

Published Sep 16, 2026

Description

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, the @orpc/server CORS plugin in packages/server/src/plugins/cors.ts copies a client's incoming Vary request header into the response instead of controlling Vary as a response-only header and using Origin for request-origin variation. In deployments behind a shared cache, CDN, or reverse proxy that keys responses using Vary, a client can inject arbitrary variation values, pollute cache keys, and cause inconsistent CORS enforcement for other clients. Default non-cached configurations have no established direct confidentiality, integrity, or availability impact. This issue is fixed in version 1.14.8.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 16, 2026
Updated Sep 16, 2026
Reserved Aug 20, 2026
CISA Vulnrichment
Updated Sep 16, 2026
NVD
Status Received
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Sep 16, 2026
Updated Sep 16, 2026
Exploited since n/a
EUVD-2026-80991 GHSA-J9V4-RHGR-4M5F