NPM · AUGUST 2026 · EARLY WARNING

Headroom LLM Proxy Vulnerability: Critical CVE-2026-77776 Alert

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.1
Affected component
cve-2026-77776 (npm)
Affected versions
>= v0.36.0, <= v0.36.0 or >= v0.35.0, <= v0.35.0 or >= v0.34.0, <= v0.34.0 or >= v0.33.0, <= v0.33.0 or >= v0.32.0, <= v0.32.0 or >= v0.31.0, <= v0.31.0 or >= v0.30.0, <= v0.30.0 or >= v0.29.0, <= v0.29.0 or >= v0.28.0, <= v0.28.0 or >= v0.27.0, <= v0.27.0 or >= v0.26.0, <= v0.26.0 or >= v0.25.0, <= v0.25.0 or >= v0.24.0, <= v0.24.0 or >= v0.23.0, <= v0.23.0 or >= v0.22.3, <= v0.22.3 or >= v0.22.2, <= v0.22.2 or >= v0.22.1, <= v0.22.1 or >= v0.22.0, <= v0.22.0 or >= v0.21.38, <= v0.21.38 or >= v0.21.37, <= v0.21.37 or >= v0.21.36, <= v0.21.36 or >= v0.21.35, <= v0.21.35 or >= v0.21.33, <= v0.21.33 or >= v0.21.34, <= v0.21.34 or >= v0.21.32, <= v0.21.32 or >= v0.21.31, <= v0.21.31 or >= v0.21.30, <= v0.21.30 or >= v0.21.29, <= v0.21.29 or >= v0.21.28, <= v0.21.28 or >= v0.21.27, <= v0.21.27 or >= v0.21.26, <= v0.21.26 or >= v0.21.25, <= v0.21.25 or >= v0.21.22, <= v0.21.22 or >= v0.21.24, <= v0.21.24 or >= v0.21.20, <= v0.21.20 or >= v0.21.23, <= v0.21.23 or >= v0.21.21, <= v0.21.21 or >= v0.21.17, <= v0.21.17 or >= v0.21.19, <= v0.21.19 or >= v0.21.18, <= v0.21.18 or >= v0.21.16, <= v0.21.16 or >= v0.21.15, <= v0.21.15 or >= v0.21.14, <= v0.21.14 or >= v0.21.13, <= v0.21.13 or >= v0.21.12, <= v0.21.12 or >= v0.21.11, <= v0.21.11 or >= v0.21.10, <= v0.21.10 or >= v0.21.9, <= v0.21.9 or >= v0.21.8, <= v0.21.8 or >= v0.21.7, <= v0.21.7 or >= v0.21.6, <= v0.21.6 or >= v0.21.5, <= v0.21.5 or >= v0.21.4, <= v0.21.4 or >= v0.21.3, <= v0.21.3 or >= v0.21.2, <= v0.21.2 or >= v0.21.1, <= v0.21.1 or >= v0.21.0, <= v0.21.0 or >= v0.20.27, <= v0.20.27 or >= v0.20.26, <= v0.20.26 or >= v0.20.25, <= v0.20.25 or >= v0.20.24, <= v0.20.24 or >= v0.20.23, <= v0.20.23 or >= v0.20.22, <= v0.20.22 or >= v0.20.21, <= v0.20.21 or >= v0.20.20, <= v0.20.20 or >= v0.20.19, <= v0.20.19 or >= v0.20.18, <= v0.20.18 or >= v0.20.17, <= v0.20.17 or >= v0.20.16, <= v0.20.16 or >= v0.20.15, <= v0.20.15 or >= v0.20.14, <= v0.20.14 or >= v0.20.13, <= v0.20.13 or >= v0.20.12, <= v0.20.12 or >= v0.20.11, <= v0.20.11 or >= v0.20.10, <= v0.20.10 or >= v0.20.9, <= v0.20.9 or >= v0.20.8, <= v0.20.8 or >= v0.20.7, <= v0.20.7 or >= v0.20.6, <= v0.20.6 or >= v0.20.5, <= v0.20.5 or >= v0.20.4, <= v0.20.4 or >= v0.20.3, <= v0.20.3 or >= v0.20.2, <= v0.20.2 or >= v0.20.1, <= v0.20.1 or >= v0.20.0, <= v0.20.0 or >= v0.19.0, <= v0.19.0 or >= v0.18.2, <= v0.18.2 or >= v0.18.0, <= v0.18.0 or >= v0.18.1, <= v0.18.1 or >= v0.17.0, <= v0.17.0 or >= v0.16.0, <= v0.16.0 or >= v0.15.1, <= v0.15.1 or >= v0.15.0, <= v0.15.0 or >= v0.14.5, <= v0.14.5 or >= v0.14.4, <= v0.14.4 or >= v0.14.3, <= v0.14.3 or >= v0.14.2, <= v0.14.2 or >= v0.10.17, <= v0.10.17 or >= v0.14.1, <= v0.14.1 or >= v0.13.5, <= v0.13.5 or >= v0.14.0, <= v0.14.0 or >= v0.13.8, <= v0.13.8 or >= v0.13.7, <= v0.13.7 or >= v0.13.6, <= v0.13.6 or >= v0.13.4, <= v0.13.4 or >= v0.13.3, <= v0.13.3 or >= v0.13.2, <= v0.13.2 or >= v0.13.1, <= v0.13.1 or >= v0.13.0, <= v0.13.0 or >= v0.12.0, <= v0.12.0 or >= v0.11.0, <= v0.11.0 or >= v0.10.19, <= v0.10.19 or >= v0.10.18, <= v0.10.18 or >= v0.10.16, <= v0.10.16 or >= v0.10.15, <= v0.10.15 or >= v0.10.14, <= v0.10.14 or >= v0.10.13, <= v0.10.13 or >= v0.10.12, <= v0.10.12 or >= v0.10.11, <= v0.10.11 or >= v0.10.10, <= v0.10.10 or >= v0.10.9, <= v0.10.9 or >= v0.10.3, <= v0.10.3 or >= v0.10.8, <= v0.10.8 or >= v0.9.7, <= v0.9.7 or >= v0.10.7, <= v0.10.7 or >= v0.10.6, <= v0.10.6 or >= v0.10.5, <= v0.10.5 or >= v0.10.4, <= v0.10.4 or >= v0.10.2, <= v0.10.2 or >= v0.10.1, <= v0.10.1 or >= v0.10.0, <= v0.10.0 or >= v0.9.6, <= v0.9.6 or >= v0.9.5, <= v0.9.5 or >= v0.9.4, <= v0.9.4 or >= v0.9.3, <= v0.9.3 or >= v0.9.2, <= v0.9.2 or >= v0.8.3, <= v0.8.3 or >= v0.9.1, <= v0.9.1 or >= v0.9.0, <= v0.9.0 or >= v0.8.2, <= v0.8.2 or >= v0.8.1, <= v0.8.1 or >= v0.8.0, <= v0.8.0 or >= v0.7.1, <= v0.7.1 or >= v0.7.4, <= v0.7.4 or >= v0.7.3, <= v0.7.3 or >= v0.7.2, <= v0.7.2 or >= v0.7.0, <= v0.7.0 or >= v0.6.7, <= v0.6.7 or >= v0.6.6, <= v0.6.6 or >= v0.6.5, <= v0.6.5 or >= v0.6.4, <= v0.6.4 or >= v0.6.3, <= v0.6.3 or >= v0.6.2, <= v0.6.2 or >= v0.6.1, <= v0.6.1 or >= v0.6.0, <= v0.6.0 or >= v0.5.28, <= v0.5.28 or >= v0.5.27, <= v0.5.27 or >= v0.5.26, <= v0.5.26 or >= v0.5.20, <= v0.5.20 or >= v0.5.2, <= v0.5.2 or >= v0.3.7, <= v0.3.7 or >= v0.3.0, <= v0.3.0 or >= v0.2.15, <= v0.2.15
Patched version
Not yet available
CVE-2026-77776

An early warning has been issued for a critical vulnerability in Headroom's LLM proxy, tracked as CVE-2026-77776, which could allow unauthorized access to user data.

What happened

Headroom's LLM proxy reportedly allows clients to read or write another user's stored LLM memory by deriving the memory owner from the x-headroom-user-id request header. This vulnerability is under investigation and has a CVSS score of 9.1. The issue arises because the header is read directly at several points in the code, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory.

The recommended fix introduces a single resolve_memory_identity seam in headroom/proxy/identity.py that honors the header only for loopback or allowlisted callers and otherwise binds the identity to the proxy-token fingerprint or the operating system user. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships with --host 0.0.0.0 and published ports, which exposes the affected data-plane routes if not configured properly.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If cve-2026-77776 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using any version of the Headroom package from v0.36.0 down to v0.2.15, inclusive.

What should I do right now?

Upgrade to the latest version of the Headroom package and ensure proper authentication is in place for the data-plane routes.

Is there an official fix available?

No official fix has been published yet. Monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats