VYPR
Vendor

Headroom

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2026-77776CriAug 21, 2026
    risk 0.52cvss 9.1epss

    Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client…

  • CVE-2026-77775HigAug 21, 2026
    risk 0.49cvss 8.6epss

    Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname,…

VYPR — Vulnerability Intelligence