Headroom LLM Proxy Vulnerability: Critical CVE-2026-77776 Alert
- Severity
- CRITICAL
- CVSS
- 9.1
- Affected component
- cve-2026-77776 (npm)
- Affected versions
- >= v0.36.0, <= v0.36.0 or >= v0.35.0, <= v0.35.0 or >= v0.34.0, <= v0.34.0 or >= v0.33.0, <= v0.33.0 or >= v0.32.0, <= v0.32.0 or >= v0.31.0, <= v0.31.0 or >= v0.30.0, <= v0.30.0 or >= v0.29.0, <= v0.29.0 or >= v0.28.0, <= v0.28.0 or >= v0.27.0, <= v0.27.0 or >= v0.26.0, <= v0.26.0 or >= v0.25.0, <= v0.25.0 or >= v0.24.0, <= v0.24.0 or >= v0.23.0, <= v0.23.0 or >= v0.22.3, <= v0.22.3 or >= v0.22.2, <= v0.22.2 or >= v0.22.1, <= v0.22.1 or >= v0.22.0, <= v0.22.0 or >= v0.21.38, <= v0.21.38 or >= v0.21.37, <= v0.21.37 or >= v0.21.36, <= v0.21.36 or >= v0.21.35, <= v0.21.35 or >= v0.21.33, <= v0.21.33 or >= v0.21.34, <= v0.21.34 or >= v0.21.32, <= v0.21.32 or >= v0.21.31, <= v0.21.31 or >= v0.21.30, <= v0.21.30 or >= v0.21.29, <= v0.21.29 or >= v0.21.28, <= v0.21.28 or >= v0.21.27, <= v0.21.27 or >= v0.21.26, <= v0.21.26 or >= v0.21.25, <= v0.21.25 or >= v0.21.22, <= v0.21.22 or >= v0.21.24, <= v0.21.24 or >= v0.21.20, <= v0.21.20 or >= v0.21.23, <= v0.21.23 or >= v0.21.21, <= v0.21.21 or >= v0.21.17, <= v0.21.17 or >= v0.21.19, <= v0.21.19 or >= v0.21.18, <= v0.21.18 or >= v0.21.16, <= v0.21.16 or >= v0.21.15, <= v0.21.15 or >= v0.21.14, <= v0.21.14 or >= v0.21.13, <= v0.21.13 or >= v0.21.12, <= v0.21.12 or >= v0.21.11, <= v0.21.11 or >= v0.21.10, <= v0.21.10 or >= v0.21.9, <= v0.21.9 or >= v0.21.8, <= v0.21.8 or >= v0.21.7, <= v0.21.7 or >= v0.21.6, <= v0.21.6 or >= v0.21.5, <= v0.21.5 or >= v0.21.4, <= v0.21.4 or >= v0.21.3, <= v0.21.3 or >= v0.21.2, <= v0.21.2 or >= v0.21.1, <= v0.21.1 or >= v0.21.0, <= v0.21.0 or >= v0.20.27, <= v0.20.27 or >= v0.20.26, <= v0.20.26 or >= v0.20.25, <= v0.20.25 or >= v0.20.24, <= v0.20.24 or >= v0.20.23, <= v0.20.23 or >= v0.20.22, <= v0.20.22 or >= v0.20.21, <= v0.20.21 or >= v0.20.20, <= v0.20.20 or >= v0.20.19, <= v0.20.19 or >= v0.20.18, <= v0.20.18 or >= v0.20.17, <= v0.20.17 or >= v0.20.16, <= v0.20.16 or >= v0.20.15, <= v0.20.15 or >= v0.20.14, <= v0.20.14 or >= v0.20.13, <= v0.20.13 or >= v0.20.12, <= v0.20.12 or >= v0.20.11, <= v0.20.11 or >= v0.20.10, <= v0.20.10 or >= v0.20.9, <= v0.20.9 or >= v0.20.8, <= v0.20.8 or >= v0.20.7, <= v0.20.7 or >= v0.20.6, <= v0.20.6 or >= v0.20.5, <= v0.20.5 or >= v0.20.4, <= v0.20.4 or >= v0.20.3, <= v0.20.3 or >= v0.20.2, <= v0.20.2 or >= v0.20.1, <= v0.20.1 or >= v0.20.0, <= v0.20.0 or >= v0.19.0, <= v0.19.0 or >= v0.18.2, <= v0.18.2 or >= v0.18.0, <= v0.18.0 or >= v0.18.1, <= v0.18.1 or >= v0.17.0, <= v0.17.0 or >= v0.16.0, <= v0.16.0 or >= v0.15.1, <= v0.15.1 or >= v0.15.0, <= v0.15.0 or >= v0.14.5, <= v0.14.5 or >= v0.14.4, <= v0.14.4 or >= v0.14.3, <= v0.14.3 or >= v0.14.2, <= v0.14.2 or >= v0.10.17, <= v0.10.17 or >= v0.14.1, <= v0.14.1 or >= v0.13.5, <= v0.13.5 or >= v0.14.0, <= v0.14.0 or >= v0.13.8, <= v0.13.8 or >= v0.13.7, <= v0.13.7 or >= v0.13.6, <= v0.13.6 or >= v0.13.4, <= v0.13.4 or >= v0.13.3, <= v0.13.3 or >= v0.13.2, <= v0.13.2 or >= v0.13.1, <= v0.13.1 or >= v0.13.0, <= v0.13.0 or >= v0.12.0, <= v0.12.0 or >= v0.11.0, <= v0.11.0 or >= v0.10.19, <= v0.10.19 or >= v0.10.18, <= v0.10.18 or >= v0.10.16, <= v0.10.16 or >= v0.10.15, <= v0.10.15 or >= v0.10.14, <= v0.10.14 or >= v0.10.13, <= v0.10.13 or >= v0.10.12, <= v0.10.12 or >= v0.10.11, <= v0.10.11 or >= v0.10.10, <= v0.10.10 or >= v0.10.9, <= v0.10.9 or >= v0.10.3, <= v0.10.3 or >= v0.10.8, <= v0.10.8 or >= v0.9.7, <= v0.9.7 or >= v0.10.7, <= v0.10.7 or >= v0.10.6, <= v0.10.6 or >= v0.10.5, <= v0.10.5 or >= v0.10.4, <= v0.10.4 or >= v0.10.2, <= v0.10.2 or >= v0.10.1, <= v0.10.1 or >= v0.10.0, <= v0.10.0 or >= v0.9.6, <= v0.9.6 or >= v0.9.5, <= v0.9.5 or >= v0.9.4, <= v0.9.4 or >= v0.9.3, <= v0.9.3 or >= v0.9.2, <= v0.9.2 or >= v0.8.3, <= v0.8.3 or >= v0.9.1, <= v0.9.1 or >= v0.9.0, <= v0.9.0 or >= v0.8.2, <= v0.8.2 or >= v0.8.1, <= v0.8.1 or >= v0.8.0, <= v0.8.0 or >= v0.7.1, <= v0.7.1 or >= v0.7.4, <= v0.7.4 or >= v0.7.3, <= v0.7.3 or >= v0.7.2, <= v0.7.2 or >= v0.7.0, <= v0.7.0 or >= v0.6.7, <= v0.6.7 or >= v0.6.6, <= v0.6.6 or >= v0.6.5, <= v0.6.5 or >= v0.6.4, <= v0.6.4 or >= v0.6.3, <= v0.6.3 or >= v0.6.2, <= v0.6.2 or >= v0.6.1, <= v0.6.1 or >= v0.6.0, <= v0.6.0 or >= v0.5.28, <= v0.5.28 or >= v0.5.27, <= v0.5.27 or >= v0.5.26, <= v0.5.26 or >= v0.5.20, <= v0.5.20 or >= v0.5.2, <= v0.5.2 or >= v0.3.7, <= v0.3.7 or >= v0.3.0, <= v0.3.0 or >= v0.2.15, <= v0.2.15
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in Headroom's LLM proxy, tracked as CVE-2026-77776, which could allow unauthorized access to user data.
What happened
Headroom's LLM proxy reportedly allows clients to read or write another user's stored LLM memory by deriving the memory owner from the x-headroom-user-id request header. This vulnerability is under investigation and has a CVSS score of 9.1. The issue arises because the header is read directly at several points in the code, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory.
The recommended fix introduces a single resolve_memory_identity seam in headroom/proxy/identity.py that honors the header only for loopback or allowlisted callers and otherwise binds the identity to the proxy-token fingerprint or the operating system user. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships with --host 0.0.0.0 and published ports, which exposes the affected data-plane routes if not configured properly.
What to do about it
- Upgrade to the latest version of the Headroom package to mitigate the vulnerability.
- Ensure proper authentication is in place for the data-plane routes to prevent unauthorized access.
- Review your deployment configurations, especially docker-compose.yml, to ensure it is not exposing the affected routes without proper security measures.
- Monitor the primary sources for updates on the vulnerability and any official fixes that may be released.
How 0Day would have caught this
cve-2026-77776 is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using any version of the Headroom package from v0.36.0 down to v0.2.15, inclusive.
What should I do right now?
Upgrade to the latest version of the Headroom package and ensure proper authentication is in place for the data-plane routes.
Is there an official fix available?
No official fix has been published yet. Monitor the primary sources for updates.