HIGH
headroomlabs-ai
CVE published 2026-09-11
CVE-2026-71416
CVE-2026-71416 is a high-severity vulnerability in the Headroom WebSocket server, which allows malicious clients to perform arbitrary LLM requests without authentication. This issue was fixed in version 0.35.0. The vulnerability arises from the server's failure to validate the `Origin` header of incoming client WebSocket requests before forwarding them to the upstream server. This oversight enables malici [truncated]