CVE-2026-77775: Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header...

Added to the CISA Known Exploited Vulnerabilities catalog on 21 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.6.

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for ...

Required action: Review and patch if applicable to your AI infrastructure.