Vibe Coding
Headroom 0.36.4 Fixes an Upstream-Validation Hole in Its Agent Proxy
Headroom, a context-compression proxy and MCP server for coding agents with 67,241 stars, shipped 0.36.4 on 22 August 2026 with a security fix that validates caller-supplied upstreams on every resolution path (PR #3195), closing a gap where some paths did not. Same-day 0.36.5 fixed Codex ChatGPT auth detection so `wrap`/`init` correctly emit `requires_openai_auth` from id_token claims, and made `doctor` report project-scoped Claude routing instead of a false negative. If you route agent traffic through a compression proxy, a caller-controlled upstream is a redirect primitive, and this release is the one to be on.
Source
↳ Follow the thread