Junglewise Threat Intelligence

CVE-2026-77776: Headroom LLM proxy authentication bypass via x-headroom-user-id header

CVE-2026-77776 · Severity: critical · CVSS 9.1 · Published 2026-08-21

Technologies: Headroom Labs Headroom. Vendors: Headroom Labs.

Executive brief

Headroom is an LLM proxy service that compresses data before sending it to language models. The proxy fails to authenticate the x-headroom-user-id request header, allowing an attacker to impersonate any user and read or modify other users' stored LLM conversation history. Default Docker deployments expose this vulnerability to the network without authentication.

Technical details

The vulnerability is an authentication bypass in Headroom's OpenAI-compatible proxy. The x-headroom-user-id header is read directly in headroom/proxy/handlers/openai.py (chat completion and websocket paths) without binding it to the actual caller's identity. An unauthenticated network attacker can craft requests with arbitrary user identifiers to access or modify other users' memory storage. The fix introduces identity validation through a resolve_memory_identity seam that honors the header only for loopback or allowlisted callers, otherwise binding identity to proxy-token fingerprint or OS user. Default Docker Compose configuration ships with --host 0.0.0.0, no HEADROOM_PROXY_TOKEN enforcement, and published ports, exposing data-plane routes to the network without authentication.

Affected products

  • Headroom Labs Headroom <0.9.0

Timeline

  • 2026-08-21: disclosed

References

Related threats