THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j9v4-rhgr-4m5f (medium) — oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass

[GHSA] GHSA-j9v4-rhgr-4m5f (medium) — oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass

medgithub_advisoriesPublished 2026-09-17

GHSA-j9v4-rhgr-4m5f Severity: medium CVE: CVE-2026-77360

oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass

### Summary A flaw in the CORS plugin allowed the incoming request's `Vary` header to be reflected into the response, letting a client influence a header that should be controlled solely by the server.

### Details The CORS plugin previously copied the reques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-j9v4-rhgr-4m5f