CVE-2026-77776: Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat comp...

Added to the CISA Known Exploited Vulnerabilities catalog on 21 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.1.

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name a...

Required action: Review and patch if applicable to your AI infrastructure.