A flaw in the CORS plugin allowed the incoming request's Vary header to be reflected into the response, letting a client influence a header that should be controlled solely by the server.
The CORS plugin previously copied the request's Vary header directly onto the response instead of treating Vary as a response-only header. Because Vary tells downstream caches and proxies how to key their cached responses, this allowed a client to inject arbitrary values into the response's Vary header, potentially distorting cache-key behavior in shared caches/CDNs sitting in front of an oRPC server and leading to inconsistent CORS enforcement for other clients.
Practical impact is limited to deployments where a shared cache or reverse proxy keys on the Vary header; the real-world effect depends on the caching layer's configuration.
May cause cache key pollution and inconsistent CORS enforcement in setups that rely on shared/edge caches keying on Vary. No direct confidentiality, integrity, or availability impact in default (non-cached) configurations.
Update @orpc/server (and any other @orpc/* packages bundling the CORS plugin) to 1.14.8. The CORS plugin now derives Vary exclusively from the response, appending Origin and preserving existing values instead of reflecting request headers.
{
"cwe_ids": [
"CWE-113"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T14:52:37Z",
"nvd_published_at": "2026-09-16T19:17:38Z",
"severity": "MODERATE"
}