← العودة للجدول
CVE-2026-71416
CVE-2026-71416 — Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
📅 2026-10-03
🟠 High 🔥 PoC Only GHSA AI Attack Linux CVSS 8.8

📋 الوصف الكامل

### Summary The Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the browse

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

AI Attack

🔗 CVE ID

CVE-2026-71416

📡 المصدر

GHSA

✅ الحلول والتخفيف

Refer to CVE-2026-71416 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←