CVE-2026-62253

critical

Description

Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches the issue.

References

https://github.com/sipcapture/homer/security/advisories/GHSA-rqcc-94gv-wjm9

https://github.com/sipcapture/homer/releases/tag/11.0.283

https://github.com/sipcapture/homer/pull/839

https://github.com/sipcapture/homer/commit/5e90809657c9df321db191a69c6050f873f5646b

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94523

Details

Source: Mitre, NVD

Published: 2026-10-07

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical