CVE-2026-71416 | headroomlabs-ai Headroom up to 0.34.x WebSocket Server Origin improper authentication

SecurityVulns

A vulnerability classified as critical was found in headroomlabs-ai Headroom up to 0.34.x. The affected element is an unknown function of the component WebSocket Server. Executing a manipulation of the argument Origin can lead to improper authentication.

This vulnerability is registered as CVE-2026-71416. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More