CVE-2026-71416 PUBLISHED

Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)

Assigner: GitHub_M
Reserved: 06.08.2026 Published: 11.09.2026 Updated: 11.09.2026

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the Origin header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the OPENAI_API_KEY environment variable. Version 0.35.0 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor headroomlabs-ai
Product headroom
Versions
  • Version < 0.35.0 is affected

References

Problem Types

  • CWE-287: Improper Authentication CWE
  • CWE-1385: Missing Origin Validation in WebSockets CWE