
CVE-2026-77776 (CVSS 9.1): Headroom's LLM proxy (http://openai.py) treats x-headroom-user-id as memory owner — no bind. Name another user's id → read/write stored LLM memory. Fixed in 0.36.1. CVE-2026-59279 + CVE-2026-64849 — no bind / no cap / no IP pin. #CVE #Python #AppSec #InfoSec
Post summary
Headroom’s LLM proxy suffered a memory ownership flaw (CVE-2026-77776, CVSS 9.1) that allowed users to read/write other users’ memory, and it has been addressed in version 0.36.1.
