CVE-2026-77776 — LLM: Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header.
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single resolve_memory_identity seam in headroom/proxy/identity.py that honors the header CVSSv3.1 9.1 (CRITICAL)