CVE-2026-71416: Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket
Summary
Headroom is a tool that compresses data before sending it to an LLM (large language model, an AI system trained on text). In versions before 0.35.0, the Headroom WebSocket server (a communication protocol allowing real-time two-way data exchange) failed to validate the Origin header (a security check that confirms where a request is coming from), allowing attackers to send unauthorized LLM requests and potentially access OpenAI API keys stored in environment variables (system settings that store sensitive information).
Solution / Mitigation
Update Headroom to version 0.35.0 or later, which fixes the issue.
Vulnerability Details
8.8(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
network
low
none
required
September 11, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-71416
First tracked: September 11, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%