PatchSiren

headroomlabs-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH headroomlabs-ai CVE published 2026-09-11

CVE-2026-71416

CVE-2026-71416 is a high-severity vulnerability in the Headroom WebSocket server, which allows malicious clients to perform arbitrary LLM requests without authentication. This issue was fixed in version 0.35.0. The vulnerability arises from the server's failure to validate the `Origin` header of incoming client WebSocket requests before forwarding them to the upstream server. This oversight enables malici [truncated]