CVE-2026-77775 | Headroom Labs up to 0.36.0 LLM Proxy openai.py x-headroom-base-url improper authorization
A vulnerability was found in Headroom Labs Headroom up to 0.36.0. It has been classified as problematic. Impacted is the function _resolve_openai_upstream_base/_select_passthrough_base_url of the file headroom/proxy/handlers/openai.py of the component LLM Proxy. The manipulation of the argument x-headroom-base-url leads to improper authorization.
This vulnerability is documented as CVE-2026-77775. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More