CVE-2026-77775Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use as the upstream base; _select_passthrough_base_url in headroom/providers/proxy_routes.py reads the same header for the passthrough routes. No check rejects loopback, link-local, or RFC 1918 destinations, and because the component is a proxy the upstream response is returned to the caller, so the request reaches internal services and cloud metadata addresses and their responses are disclosed. The Authorization header accompanying the request is forwarded unchanged to the caller-designated host. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships --host 0.0.0.0 with published ports and no required HEADROOM_PROXY_TOKEN, which the server itself warns about at startup, so a deployment following the shipped compose exposes the affected data-plane routes to the network without authentication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Technical Details · 2026-08-21: 208-21
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-77775 Headroom LLM Proxy Allows Disclosure of Internal Services... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-77775 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post cites CVE‑2026‑77775 and directs readers to a vulnerability database, but offers no technical, exploit, or mitigation details.

    10030199
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨HIGH - Headroom LLM Proxy SSRF via x-headroom-base-url (CVE-2026-77775) Headroom’s proxy honors the client-supplied x-headroom-base-url to select the upstream without blocking loopback/link-local/RFC1918, enabling SSRF to internal services and cloud metadata and returning the response to the caller. The proxy also forwards the Authorization header to the attacker-chosen host; the reference docker-compose binds 0.0.0.0 with published ports and no proxy token, exposing routes unauthenticated. 👉Affected: headroom-ai (all versions)

    Post summary

    High‑severity SSRF vulnerability disclosed for Headroom LLM Proxy via x-headroom-base-url, enabling internal service access and unauthorized header forwarding; no patch or exploit information provided.

    00010109
    291 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-77775 Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolv… CVSS 8.6 Full analysis → https://sec.kaitan.id/cves/CVE-2026-77775 #OpenAI #CyberSecurity #InfoSec

    Post summary

    This tweet announces a new high-severity CVE (CVE-2026-77775) affecting Headroom's LLM proxy, highlighting a header-based upstream selection flaw, and links to a detailed analysis.

    0000030
    80 followersView on X

Explore more