All 2 CVE vulnerabilities found in Headroom, with AI-generated Chinese analysis, references, and POCs.
Vendor: Headroom Labs
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-77776 | Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity CWE-639 | 9.1 | Critical | 2026-08-21 |
| CVE-2026-77775 | Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Validation CWE-918 | 8.6 | High | 2026-08-21 |
All 2 known CVE vulnerabilities affecting Headroom with full Chinese analysis, references, and POCs where available.