High severity8.8NVD Advisory· Published Sep 11, 2026· Updated Sep 11, 2026
CVE-2026-71416
CVE-2026-71416
Description
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the Origin header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the OPENAI_API_KEY environment variable. Version 0.35.0 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<0.35.0+ 1 more
- (no CPE)range: <0.35.0
- (no CPE)
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.