CVE-2026-103918: CVE-2026-103918: Prototype Injection and Denial of Service in oRPC @orpc/zod Smart Coercion Engine

# security# cve# cybersecurity
CVE-2026-103918: CVE-2026-103918: Prototype Injection and Denial of Service in oRPC @orpc/zod Smart Coercion EngineCVE Reports

CVE-2026-103918: Prototype Injection and Denial of Service in oRPC @orpc/zod Smart Coercion...

CVE-2026-103918: Prototype Injection and Denial of Service in oRPC @orpc/zod Smart Coercion Engine

Vulnerability ID: CVE-2026-103918
CVSS Score: 6.5
Published: 2026-10-05

CVE-2026-103918 is a medium-severity vulnerability within the @orpc/zod smart coercion plugin in oRPC. Prior to version 1.14.10, the package fails to sanitize untrusted input keys when performing pre-validation type coercion, allowing prototype injection on the returned request object and Denial of Service.

TL;DR

A prototype injection and denial of service vulnerability in oRPC's @orpc/zod pre-validation coercion engine enables request object prototype modification and unhandled TypeError crashes.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-915 / CWE-1321
  • Attack Vector: Network
  • CVSS v3.1 Score: 6.5 (Medium)
  • EPSS Score: 0.00234
  • Impact: Prototype Pollution / Denial of Service
  • Exploit Status: PoC available in test cases
  • KEV Status: Not listed

Affected Systems

  • oRPC
  • @orpc/zod
  • middleapi orpc
  • @orpc/zod: < 1.14.10 (Fixed in: 1.14.10)

Code Analysis

Commit: 26314df

Fix prototype pollution in zod coercion plugin by using NullProtoObj and Object.hasOwn checks.

Exploit Details

Mitigation Strategies

  • Upgrade @orpc/zod to version 1.14.10 or higher.
  • Sanitize untrusted input keys prior to oRPC coercion to filter out proto and constructor properties.

Remediation Steps:

  1. Run 'npm install @orpc/zod@1.14.10' or update the package.json file to require version 1.14.10.
  2. Verify the installation using 'npm list @orpc/zod'.
  3. Deploy input-sanitizing WAF rules if immediate patching is not possible.

References


Read the full report for CVE-2026-103918 on our website for more details including interactive diagrams and full exploit analysis.