CVE-2026-77776 | Headroom Labs up to 0.36.0 resolve_memory_identity openai.py x-headroom-user-id privileges management
A vulnerability was found in Headroom Labs Headroom up to 0.36.0. It has been declared as critical. The affected element is an unknown function of the file headroom/proxy/handlers/openai.py of the component resolve_memory_identity. The manipulation of the argument x-headroom-user-id results in improper privilege management.
This vulnerability is reported as CVE-2026-77776. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More