CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server
Vulnerability ID: CVE-2026-71416
CVSS Score: 8.8
Published: 2026-10-02
A critical cross-site WebSocket hijacking (CSWSH) vulnerability in headroomlabs-ai/headroom prior to version 0.35.0 allows unauthorized external origins to establish connection channels to the Headroom proxy, enabling arbitrary prompt execution and remote code execution through local tool integration.
TL;DR
Headroom proxy prior to v0.35.0 fails to validate the Origin header during WebSocket handshakes, allowing malicious websites to hijack connections, abuse ambient API credentials, and execute arbitrary commands.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-1385 (Missing Origin Validation in WebSockets)
- Attack Vector: Network (Requires User Interaction)
- CVSS v3.1 Score: 8.8
- EPSS Score: 0.00219 (Percentile: 11.24%)
- Exploit Status: Proof of Concept (PoC) available
- CISA KEV Status: Not Listed
Affected Systems
- headroomlabs-ai/headroom
-
headroom: < 0.35.0 (Fixed in:
v0.35.0)
Code Analysis
Commit: c632023
Secure websocket endpoint with origin validation
Mitigation Strategies
- Upgrade Headroom proxy to version v0.35.0 or later.
- Restrict the service listening interface specifically to 127.0.0.1 to avoid intranet exploitation.
- Configure explicit allowed origins via the HEADROOM_WS_ORIGINS environment variable.
- Avoid the use of wildcard '*' origin mappings in production networks.
Remediation Steps:
- Identify active Headroom proxy service installations and verify their version using command line tools or build manifests.
- Stop the active Headroom server daemon.
- Update the executable package to version 0.35.0 using the standard package manager or source rebuild.
- Configure the HEADROOM_WS_ORIGINS environment variable to represent the precise domain of authorized clients.
- Restart the Headroom service and verify that requests containing unauthorized Origin headers are rejected with code 1008.
References
- GitHub Security Advisory GHSA-h46j-26q3-rggf
- Fix Commit c632023cc1ec61d15f8f8e86efe3b54d51604a64
- Headroom Release v0.35.0
- NVD - CVE-2026-71416 Details
Read the full report for CVE-2026-71416 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)