mediumVulnerability

CVE-2026-77360

### Summary A flaw in the CORS plugin allowed the incoming request's `Vary` header to be reflected into the response, letting a client influence a header that should be controlled solely by the server. ### Details The CORS plugin previously copied the request's `Vary` header directly onto the response instead of treating `Vary` as a response-only header. Because `Vary` tells downstream caches and proxies how to key their cached responses, this allowed a client to inject arbitrary values into the response's `Vary` header, potentially distorting cache-key behavior in shared caches/CDNs sitting in front of an oRPC server and leading to inconsistent CORS enforcement for other clients. Practical impact is limited to deployments where a shared cache or reverse proxy keys on the `Vary` header; the real-world effect depends on the caching layer's configuration. ### Impact May cause cache key pollution and inconsistent CORS enforcement in setups that rely on shared/edge caches keying on `Vary`. No direct confidentiality, integrity, or availability impact in default (non-cached) configurations. ### Resolution Update `@orpc/server` (and any other `@orpc/*` packages bundling the CORS plugin) to `1.14.8`. The CORS plugin now derives `Vary` exclusively from the response, appending `Origin` and preserving existing values instead of reflecting request headers.

Properties

ghsa_id
GHSA-j9v4-rhgr-4m5f
severity
medium
summary
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
cve_id
CVE-2026-77360
signal_observed_at
2026-09-17T21:32:40+00:00
is_ghsa_only
false
ghsa_published
2026-09-17T14:52:37Z
source_url
https://github.com/advisories/GHSA-j9v4-rhgr-4m5f
ghsa_updated
2026-09-17T14:52:41Z

Related Entities (4)

AFFECTS (1)

[Software]npm/@orpc/server

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/@orpc/server

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77360 — Ninja Signal Threat Intelligence | Ninja Signal