SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-71869

CRITICAL · CVSS 9.3 EPSS 0.61% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A critical vulnerability exists in Orval versions prior to 8.21.0, where unsafe encoding of user-controlled expressions in array item defaults can lead to arbitrary code execution upon importing the generated zod schema module. This poses a significant risk to developers and organizations utilizing Java for application development, particularly in CI and testing environments. Immediate prioritization is recommended for those using affected versions to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-71869
Severity
CRITICAL
CVSS
9.3
EPSS
0.61%
Java

Original NVD Description

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted by zod schema generation without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts function formatDefaultValue. This issue is fixed in version 8.21.0.