Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-71416— Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)

Quick assessment

Affected
headroomlabs-ai headroom
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Headroom 在数据到达大型语言模型(LLM)之前会对数据进行压缩。在 0.35.0 版本之前,Headroom 的 WebSocket 服务器在将请求转发给上游服务器之前,未对传入的客户端 WebSocket 请求的 头进行验证,这使得恶意的 WebSocket 客户端能够在没有身份验证的情况下发起任意的 LLM 请求。如果恶意 WebSocket 客户端在传统浏览器或无头浏览器(如 lightpanda)中运行,且该浏览器能够访问 Headroom 代理,并且 OpenAI API 密钥存储在 环境变量中,

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71416

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
Source: CVE Program / CVE List V5
Vulnerability Description
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browser has access to the Headroom proxy and the OpenAI API key is stored in the `OPENAI_API_KEY` environment variable. Version 0.35.0 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
headroomlabs-ai headroom < 0.35.0 -

II. Public POCs for CVE-2026-71416

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71416

登录查看更多情报信息。

Vendor Advisories for CVE-2026-71416 (1)

Vendor Pages for CVE-2026-71416 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-71416

No comments yet


Leave a comment