{"id":"CVE-2026-62253","title":"Homer is open source telecom observability software","summary":"Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == \"\"`. The JWT secret defaults to an empt…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-306"],"vendor":"sipcapture","product":"homer","affected":["homer < 11.0.283"],"patched":["github.com/sipcapture/homer-app 0.0.0-20260625093330-5e90809657c9"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:56.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62253","references":[{"url":"https://github.com/sipcapture/homer/commit/5e90809657c9df321db191a69c6050f873f5646b","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/pull/839","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/releases/tag/11.0.283","label":"security-advisories@github.com"},{"url":"https://github.com/sipcapture/homer/security/advisories/GHSA-rqcc-94gv-wjm9","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-rqcc-94gv-wjm9"}],"tags":["nvd","cve.org","ghsa","go"],"aliases":["GHSA-rqcc-94gv-wjm9"],"ecosystem":"go","ingestedAt":"2026-10-07T16:38:22.236Z","slug":"CVE-2026-62253","body":"## Overview\n\nHomer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == \"\"`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-62253)\n\nAffected packages:\n\n- `github.com/sipcapture/homer-app < 0.0.0-20260625093330-5e90809657c9`\n\nPatched in:\n\n- `github.com/sipcapture/homer-app 0.0.0-20260625093330-5e90809657c9`\n\nSource: https://github.com/advisories/GHSA-rqcc-94gv-wjm9","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}