Fetching from the wire…
Public story · 2026-08-23 · high
The compression proxy fixed a validation gap where a caller-controlled upstream could act as a redirect, then patched Codex auth the same day.
Why now: Headroom followed 0.36.4 with 0.36.5 the same day, August 22, fixing Codex ChatGPT auth detection.
Headroom shipped version 0.36.4 on August 22, closing a validation gap in its agent proxy, per the release notes. Route agent traffic through Headroom and an unvalidated upstream becomes a redirect primitive. A request meant for one destination can get sent somewhere else instead.
The project is a context-compression proxy and MCP server with 67,241 stars on GitHub. As an MCP server, it sits in the same path agents use to reach tools and models. Some resolution paths were checking caller-supplied upstreams and some weren't. PR #3195 closes that gap, validating every path, according to the pull request.
The same day, Headroom shipped 0.36.5, fixing Codex ChatGPT auth detection, the notes say. Two releases in one day on a proxy this widely deployed reads as the maintainers moving fast once they'd found the gap.
The release notes don't say whether the gap was exploited before the patch landed. Anyone running Headroom in front of agent traffic should be on 0.36.5, not 0.36.4 alone.
Each link below shares sources, entities, or timing with this story.
headroom uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (headroom uses MCP); both cover August, MCP, Same; reported by the same outlet (github.com).
Linked by a graph relationship (headroom uses MCP); both cover August, MCP, Same; reported by the same outlet (github.com).
Linked by a graph relationship (headroom uses MCP); both cover August, MCP; reported by the same outlet (github.com).
headroom uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (headroom uses MCP); both cover August, MCP; reported by the same outlet (github.com).
headroom uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (headroom uses MCP); both cover August, MCP; reported by the same outlet (github.com).
Linked by a graph relationship (headroom uses MCP); both cover August, MCP; reported by the same outlet (github.com).
headroom uses LLM / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (headroom uses LLM); both cover August, MCP, Same; overlapping topics (agent, august).
headroom uses MCP / Shared entities / Same source domain / What happened next
Linked by a graph relationship (headroom uses MCP); both cover August, MCP, Same; reported by the same outlet (github.com).