← Back to CVE List
Vulnerability Intelligence Report
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)

CVE-2026-71416

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the `OPENAI_API_KEY` environment variable. Version 0.35.0 fixes the issue.

Authentication Bypass No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-287 ↗CWE-287: Improper Authentication
CWE-1385 ↗CWE-1385: Missing Origin Validation in WebSockets

Affected Products & Versions

Vendor Product Affected Versions
headroomlabs-ai headroom < 0.35.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Authentication Bypass

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-08-06T16:28:51
Published2026-09-11T13:34:38
Last Updated2026-09-11T14:33:18

LINK COPIED TO CLIPBOARD