{"id":"CVE-2026-62251","title":"Homer is open source telecom observability software","summary":"Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used …","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-89"],"vendor":"sipcapture","product":"homer","affected":["homer < 11.0.283"],"patched":["github.com/sipcapture/homer-app 0.0.0-20260625085520-a7d027dc684b"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:56.303","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62251","references":[{"url":"https://github.com/sipcapture/homer/commit/a7d027dc684b210b62285c49f555ac88d64f35f0","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/pull/837","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/releases/tag/11.0.283","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/security/advisories/GHSA-f46q-3v67-fmm4","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-f46q-3v67-fmm4"}],"tags":["nvd","cve.org","ghsa","go"],"aliases":["GHSA-f46q-3v67-fmm4"],"ecosystem":"go","ingestedAt":"2026-10-07T16:38:22.235Z","slug":"CVE-2026-62251","body":"## Overview\n\nHomer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-62251)\n\nAffected packages:\n\n- `github.com/sipcapture/homer-app < 0.0.0-20260625085520-a7d027dc684b`\n\nPatched in:\n\n- `github.com/sipcapture/homer-app 0.0.0-20260625085520-a7d027dc684b`\n\nSource: https://github.com/advisories/GHSA-f46q-3v67-fmm4","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}