CORS Plugin Vulnerability in oRPC Affects API Security
CVE-2026-77360
6.3MEDIUM
What is CVE-2026-77360?
The oRPC tool, designed for creating type-safe APIs compliant with OpenAPI standards, has a vulnerability in its CORS plugin prior to version 1.14.8. This misconfiguration allows a client's 'Vary' request header to be improperly copied into the response, permitting attackers to manipulate response caching for clients behind shared caches, CDNs, or reverse proxies. Consequently, an adversary could inject arbitrary values, leading to inconsistent enforcement of CORS policies across different clients. Although default configurations may not directly impact confidentiality, integrity, or availability, users are advised to upgrade to version 1.14.8 to mitigate potential risks and ensure robust API security.
Affected Version(s)
orpc < 1.14.8
