{"id":"CVE-2026-71864","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-71864","summary":"Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into…","details":"Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into the generated request-validation zod.object({...}) schema without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts and header request-validation generation. This issue is fixed in version 8.21.0.","published":"2026-08-19T18:17:23.313","modified":"2026-08-19T18:17:23.313","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/orval-labs/orval/commit/8ef1bfdf3f9bcaf9dabfbe2e42887f1c0e159ab6","label":"orval-labs/orval@8ef1bfd"},"references":[{"type":"WEB","url":"https://github.com/orval-labs/orval/commit/8ef1bfdf3f9bcaf9dabfbe2e42887f1c0e159ab6"},{"type":"WEB","url":"https://github.com/orval-labs/orval/pull/3692"},{"type":"WEB","url":"https://github.com/orval-labs/orval/releases/tag/v8.21.0"},{"type":"WEB","url":"https://github.com/orval-labs/orval/security/advisories/GHSA-6437-gxhq-pqv8"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T18:17:23.313"}}