Browse all 5 CVE security advisories affecting middleapi. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-103918 | @orpc/zod: Prototype injection in smart coercion — orpc CWE-915 | 6.5 | Medium | 2026-10-02 |
| CVE-2026-103036 | @orpc/json-schema: Prototype injection in smart coercion — orpc CWE-915 | 6.5 | Medium | 2026-10-02 |
| CVE-2026-77360 | oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass — orpc CWE-113 | 6.3 | Medium | 2026-09-16 |
| CVE-2026-33331 | oRPC: Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify — orpc CWE-79 | 8.2 | High | 2026-03-24 |
| CVE-2026-28794 | oRPC: Prototype Pollution in `@orpc/client` via `StandardRPCJsonSerializer` Deserialization — orpc CWE-1321 | 9.8 | - | 2026-03-06 |
This page lists every published CVE security advisory associated with middleapi. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.