PatchSiren

Headroom Labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Headroom Labs CVE published 2026-08-21

CVE-2026-77776

The Headroom LLM proxy is vulnerable due to improper validation of the x-headroom-user-id request header, allowing unauthorized access to stored LLM memory. This issue affects organizations using the proxy, especially those with exposed data-plane routes to the network without authentication. The vulnerability enables clients to access or modify other users' stored LLM memory. The fix introduces a resolve [truncated]

HIGH Headroom Labs CVE published 2026-08-21

CVE-2026-77775

The Headroom LLM proxy vulnerability (CVE-2026-77775) is a critical issue that allows a client to specify the upstream base URL via the x-headroom-base-url request header without adequate validation. This oversight enables requests to be forwarded to internal services, cloud metadata addresses, and their responses disclosed, potentially leading to unauthorized access and data exposure. The vulnerability i [truncated]