GHSA-j9v4-rhgr-4m5fMedium

oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass

Published
September 17, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

A flaw in the CORS plugin allowed the incoming request's Vary header to be reflected into the response, letting a client influence a header that should be controlled solely by the server.

Details

The CORS plugin previously copied the request's Vary header directly onto the response instead of treating Vary as a response-only header. Because Vary tells downstream caches and proxies how to key their cached responses, this allowed a client to inject arbitrary values into the response's Vary header, potentially distorting cache-key behavior in shared caches/CDNs sitting in front of an oRPC server and leading to inconsistent CORS enforcement for other clients.

Practical impact is limited to deployments where a shared cache or reverse proxy keys on the Vary header; the real-world effect depends on the caching layer's configuration.

Impact

May cause cache key pollution and inconsistent CORS enforcement in setups that rely on shared/edge caches keying on Vary. No direct confidentiality, integrity, or availability impact in default (non-cached) configurations.

Resolution

Update @orpc/server (and any other @orpc/* packages bundling the CORS plugin) to 1.14.8. The CORS plugin now derives Vary exclusively from the response, appending Origin and preserving existing values instead of reflecting request headers.

🎯 Affected products1

  • npm/@orpc/server:<= 1.14.7

🔗 References (7)