SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-71864

CRITICAL · CVSS 9.3 EPSS 0.61% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Orval versions prior to 8.21.0 are vulnerable due to improper handling of double quotes in header parameter names, which can lead to the generation of unsafe JavaScript code in the request-validation schema. This flaw allows for potential code execution in various environments, including development and CI/CD pipelines, making it critical for developers and organizations using Orval to upgrade to version 8.21.0 immediately to mitigate this risk. Prioritization is essential for teams relying on JavaScript clients generated from OpenAPI specifications to ensure the security of their applications.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71864
Severity
CRITICAL
CVSS
9.3
EPSS
0.61%
Java

Original NVD Description

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into the generated request-validation zod.object({...}) schema without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts and header request-validation generation. This issue is fixed in version 8.21.0.