GHSA-j9v4-rhgr-4m5f
MODERATECVE-2026-77360A flaw in the CORS plugin allowed the incoming request's Vary header to be reflected into the response, letting a client influence a header that should be controlled solely by the server.
- Affected
- <= 1.14.7
- Fixed in
- 1.14.8
- Weakness
- CWE-113
- Published
- 2026-09-17
- Source
- github