CVE-2026-77776Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single resolve_memory_identity seam in headroom/proxy/identity.py that honors the header only for loopback or allowlisted callers and otherwise binds the identity to the proxy-token fingerprint or the operating system user. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships --host 0.0.0.0 with published ports and no required HEADROOM_PROXY_TOKEN, which the server itself warns about at startup, so a deployment following the shipped compose exposes the affected data-plane routes to the network without authentication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Patch / Workaround · 2026-08-21: 2Technical Details · 2026-08-21: 308-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Innora.ai@Innora_sg
    Patch

    CVE-2026-77776 (CVSS 9.1): Headroom's LLM proxy (http://openai.py) treats x-headroom-user-id as memory owner — no bind. Name another user's id → read/write stored LLM memory. Fixed in 0.36.1. CVE-2026-59279 + CVE-2026-64849 — no bind / no cap / no IP pin. #CVE #Python #AppSec #InfoSec

    Post summary

    Headroom’s LLM proxy (http://openai.py) improperly treats the x-headroom-user-id header as a memory owner, enabling arbitrary users to read/write stored LLM memory, with CVE-2026-77776 scoring CVSS 9.1. The issue is fixed in version 0.36.1.

    0000061
    23 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-77776 - Critical IDOR in Headroom LLM proxy. Spoof x-headroom-user-id to read/write other users' memory. CVSS 9.1. No patch yet - restrict access now. #CVE #Headroom #infosec https://www.valtersit.com/cve/CVE-2026-77776/ #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #iceland #israel

    Post summary

    A new critical IDOR vulnerability (CVE‑2026‑77776) in Headroom LLM proxy is announced with a CVSS of 9.1 and an immediate access restriction recommendation, but no PoC, exploit code, or evidence of active exploitation is mentioned.

    0000052
    1.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-77776 Headroom LLM Proxy Memory Access Vulnerability Exposes User Data https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-77776

    Post summary

    A newly disclosed CVE-2026-77776 describes a memory‑access flaw that exposes user data, but no PoC, exploit, patch, or active exploitation details are provided.

    00000115
    4.1K followersView on X

Explore more