DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-71416: CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server

CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server

Vulnerability ID: CVE-2026-71416
CVSS Score: 8.8
Published: 2026-10-02

A critical cross-site WebSocket hijacking (CSWSH) vulnerability in headroomlabs-ai/headroom prior to version 0.35.0 allows unauthorized external origins to establish connection channels to the Headroom proxy, enabling arbitrary prompt execution and remote code execution through local tool integration.

TL;DR

Headroom proxy prior to v0.35.0 fails to validate the Origin header during WebSocket handshakes, allowing malicious websites to hijack connections, abuse ambient API credentials, and execute arbitrary commands.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-1385 (Missing Origin Validation in WebSockets)
  • Attack Vector: Network (Requires User Interaction)
  • CVSS v3.1 Score: 8.8
  • EPSS Score: 0.00219 (Percentile: 11.24%)
  • Exploit Status: Proof of Concept (PoC) available
  • CISA KEV Status: Not Listed

Affected Systems

  • headroomlabs-ai/headroom
  • headroom: < 0.35.0 (Fixed in: v0.35.0)

Code Analysis

Commit: c632023

Secure websocket endpoint with origin validation

Mitigation Strategies

  • Upgrade Headroom proxy to version v0.35.0 or later.
  • Restrict the service listening interface specifically to 127.0.0.1 to avoid intranet exploitation.
  • Configure explicit allowed origins via the HEADROOM_WS_ORIGINS environment variable.
  • Avoid the use of wildcard '*' origin mappings in production networks.

Remediation Steps:

  1. Identify active Headroom proxy service installations and verify their version using command line tools or build manifests.
  2. Stop the active Headroom server daemon.
  3. Update the executable package to version 0.35.0 using the standard package manager or source rebuild.
  4. Configure the HEADROOM_WS_ORIGINS environment variable to represent the precise domain of authorized clients.
  5. Restart the Headroom service and verify that requests containing unauthorized Origin headers are rejected with code 1008.

References


Read the full report for CVE-2026-71416 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)