THREAT OPS › Threat News › [GHSA] GHSA-j9v4-rhgr-4m5f (medium) — oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
[GHSA] GHSA-j9v4-rhgr-4m5f (medium) — oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
GHSA-j9v4-rhgr-4m5f Severity: medium CVE: CVE-2026-77360
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
### Summary A flaw in the CORS plugin allowed the incoming request's `Vary` header to be reflected into the response, letting a client influence a header that should be controlled solely by the server.
### Details The CORS plugin previously copied the reques
Indicators of compromise
- CVE-2026-77360cve
Original source: https://github.com/advisories/GHSA-j9v4-rhgr-4m5f