oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
A flaw in the CORS plugin allowed the incoming request's Vary header to be reflected into the response, letting a client influence a header that should be controlled solely by the server.