CVE ReportsCVE-2026-103918: Prototype Injection and Denial of Service in oRPC @orpc/zod Smart Coercion...
Vulnerability ID: CVE-2026-103918
CVSS Score: 6.5
Published: 2026-10-05
CVE-2026-103918 is a medium-severity vulnerability within the @orpc/zod smart coercion plugin in oRPC. Prior to version 1.14.10, the package fails to sanitize untrusted input keys when performing pre-validation type coercion, allowing prototype injection on the returned request object and Denial of Service.
A prototype injection and denial of service vulnerability in oRPC's @orpc/zod pre-validation coercion engine enables request object prototype modification and unhandled TypeError crashes.
1.14.10)Fix prototype pollution in zod coercion plugin by using NullProtoObj and Object.hasOwn checks.
Remediation Steps:
Read the full report for CVE-2026-103918 on our website for more details including interactive diagrams and full exploit analysis.