All 5 CVE vulnerabilities found in orpc, with AI-generated Chinese analysis, references, and POCs.
Vendor: middleapi
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-103918 | @orpc/zod: Prototype injection in smart coercion CWE-915 | 6.5 | Medium | 2026-10-02 |
| CVE-2026-103036 | @orpc/json-schema: Prototype injection in smart coercion CWE-915 | 6.5 | Medium | 2026-10-02 |
| CVE-2026-77360 | oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass CWE-113 | 6.3 | Medium | 2026-09-16 |
| CVE-2026-33331 | oRPC: Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify CWE-79 | 8.2 | High | 2026-03-24 |
| CVE-2026-28794 | oRPC: Prototype Pollution in `@orpc/client` via `StandardRPCJsonSerializer` Deserialization CWE-1321 | 9.8 | - | 2026-03-06 |
All 5 known CVE vulnerabilities affecting orpc with full Chinese analysis, references, and POCs where available.