Unvalidated Proxy Request Vulnerability in Headroom's LLM Proxy
CVE-2026-77775
7.7HIGH
What is CVE-2026-77775?
The Headroom LLM Proxy allows clients to specify the upstream destination via the 'x-headroom-base-url' header. This implementation, found in versions v0.29.0 and v0.36.1, lacks sufficient validation checks for the header value, which can lead to unintended access to internal services. The proxy forwards requests and responses without authentication, making exposed data-plane routes susceptible to unauthorized access. Notably, the server's default Docker configuration binds to all interfaces, increasing the risk of arbitrary network exposure.
Affected Version(s)
Headroom 0 < 0.36.1
Headroom 0.36.1
