Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-77776

Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity
Back to all
CVE

CVE-2026-77776

Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single resolvememoryidentity seam in headroom/proxy/identity.py that honors the header only for loopback or allowlisted callers and otherwise binds the identity to the proxy-token fingerprint or the operating system user. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships --host 0.0.0.0 with published ports and no required HEADROOMPROXYTOKEN, which the server itself warns about at startup, so a deployment following the shipped compose exposes the affected data-plane routes to the network without authentication.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.3
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://pypi.org, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77776.json, https://nvd.nist.gov/vuln/detail/CVE-2026-77776, https://www.vulncheck.com/advisories/headroom-proxy-treats-the-client-supplied-x-headroom-user-id-header-as-an-authenticated-identity, https://github.com/headroomlabs-ai/headroom/pull/2207, https://github.com/headroomlabs-ai/headroom, https://github.com/headroomlabs-ai/headroom/blob/v0.29.0/headroom/proxy/handlers/openai.py, https://github.com/headroomlabs-ai/headroom/blob/v0.36.1/headroom/proxy/identity.py

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00613%
EPSS Percentile
0.47243%
Introduced Version
0
Fix Available
37faf2f24724370483b1819b0921c899791bedc7

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading