Unvalidated Proxy Request Vulnerability in Headroom's LLM Proxy
CVE-2026-77775

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-77775?

The Headroom LLM Proxy allows clients to specify the upstream destination via the 'x-headroom-base-url' header. This implementation, found in versions v0.29.0 and v0.36.1, lacks sufficient validation checks for the header value, which can lead to unintended access to internal services. The proxy forwards requests and responses without authentication, making exposed data-plane routes susceptible to unauthorized access. Notably, the server's default Docker configuration binds to all interfaces, increasing the risk of arbitrary network exposure.

Affected Version(s)

Headroom 0 < 0.36.1

Headroom 0.36.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gregory Tan (Grg0rry)
.