VYPR

headroom

by Headroomlabs AI

CVEs (1)

  • CVE-2026-77776CriAug 21, 2026
    risk 0.52cvss 9.1epss 0.00

    Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client…