Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the `OPENAI_API_KEY` environment variable. Version 0.35.0 fixes the issue. | |
| Title | Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) | |
| Weaknesses | CWE-1385 CWE-287 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-11T14:33:18.586Z
Reserved: 2026-08-06T16:28:51.181Z
Link: CVE-2026-71416
No data.
Status : Received
Published: 2026-09-11T14:17:32.390
Modified: 2026-09-11T14:17:32.390
Link: CVE-2026-71416
No data.
OpenCVE Enrichment
No data.