CVE-2026-77776 – Headroom
CVSS 9.1
CRITICAL
Critical - Same Day Deployment
“A trusted identity header can expose one user’s AI memory to another.”
Headroom fixed a critical authorization flaw in its LLM proxy that allowed clients to supply another user’s identifier and read or modify that user’s stored LLM memory. CVE-2026-77776 affects versions before 0.36.1. The CVSS score is 9.1, which is Critical severity.
The fix strengthens memory identity handling by restricting when the user-supplied header is trusted and otherwise binding identity to the authenticated caller or local operating system user.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-639
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.