CVE-2026-77776: Authorization Bypass Through User-Controlled Key in Headroom Labs Headroom
Description
Headroom Labs Headroom prior to version 0.36.1 contains an authorization bypass vulnerability where the memory owner is derived directly from a user-controlled HTTP header (x-headroom-user-id) without proper binding to the caller's identity. This allows an attacker to impersonate other users and access or modify their stored LLM memory. The default deployment configuration exposes affected routes without authentication, increasing risk. A fix is available that restricts header usage to loopback or allowlisted callers and binds identity to proxy-token fingerprints or OS users.
CVSS v3.1
Score 9.1critical
Affected software
Headroom Labs
Headroom
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Headroom Labs Headroom involves the LLM proxy deriving the memory owner from the x-headroom-user-id HTTP request header, which is user-controlled and unchecked. This header is used in multiple request handling points, including chat completion and websocket paths, allowing an attacker to specify another user's identifier and read or write that user's stored LLM memory. The default docker-compose deployment exposes these routes publicly without requiring authentication, exacerbating the risk. The fix introduces a resolve_memory_identity function that restricts the header's use to loopback or allowlisted callers and otherwise binds identity to the proxy-token fingerprint or OS user. The vulnerability affects versions prior to 0.36.1.
Potential Impact
An unauthenticated remote attacker can bypass authorization controls by specifying arbitrary user identifiers in the x-headroom-user-id header, enabling unauthorized reading and writing of other users' stored LLM memory. This leads to a complete confidentiality and integrity compromise of user data stored in the LLM memory. The vulnerability does not affect availability. The CVSS score is 9.1 (critical), reflecting network attack vector, no privileges required, no user interaction, and high confidentiality and integrity impact.
Mitigation Recommendations
A fix is available in Headroom version 0.36.1 that properly restricts the use of the x-headroom-user-id header to loopback or allowlisted callers and binds user identity to proxy-token fingerprints or operating system users. Users should upgrade to version 0.36.1 or later. Additionally, deployments should avoid exposing the server on 0.0.0.0 without authentication tokens (HEADROOM_PROXY_TOKEN). The default pip console script binds to 127.0.0.1, which is safer. Until patched, restrict network exposure of the affected routes and require authentication tokens.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-21T11:09:25.553Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a883893acd9273b49123406
Added to database: 08/21/2026, 11:37:55 UTC
Last enriched: 09/10/2026, 18:24:28 UTC
Last updated: 10/04/2026, 18:53:18 UTC
Views: 91
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.