Junglewise Threat Intelligence

CVE-2026-77775: Headroom LLM proxy SSRF via x-headroom-base-url header

CVE-2026-77775 · Severity: high · CVSS 8.6 · Published 2026-08-21

Technologies: Headroom Labs Headroom. Vendors: Headroom Labs.

Executive brief

Headroom is an LLM proxy server that compresses tool outputs and logs before sending them to language models. A critical security flaw allows unauthenticated clients to redirect traffic to arbitrary internal network addresses and cloud metadata services by manipulating the x-headroom-base-url request header, exposing sensitive internal data and authentication credentials. The default Docker deployment is particularly vulnerable, binding to all network interfaces without authentication protection.

Technical details

This is a Server-Side Request Forgery (SSRF) vulnerability in the request header validation logic. The _resolve_openai_upstream_base function in headroom/proxy/handlers/openai.py and _select_passthrough_base_url in headroom/providers/proxy_routes.py accept the x-headroom-base-url header value and validate only that it contains a valid HTTP/HTTPS URL with a hostname, without rejecting loopback (127.0.0.1), link-local, or RFC 1918 private address ranges. Because the proxy returns the upstream response to the caller, an attacker can access internal services and cloud metadata endpoints (e.g., AWS IMDSv2). Additionally, the Authorization header is forwarded unchanged to the attacker-controlled destination, disclosing authentication credentials. The vulnerability is network-reachable in default Docker deployments (which bind 0.0.0.0 with no HEADROOM_PROXY_TOKEN requirement) but mitigated in pip console script deployments that bind only 127.0.0.1 by default.

Affected products

  • Headroom Labs Headroom <UNKNOWN>

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: advisory: CVE-2026-77775

References

Related threats