CVE-2026-62251High· 8.1▾ TwilightHomer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Homer is open source telecom observability software. Prior to version 11.0.283, the V4StatisticsQuery handler passes the user-supplied rawquery field directly to DuckDB without calling the sqlvalidator.ValidateRawSQL function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/sipcapture/homer-app < 0.0.0-20260625085520-a7d027dc684bPatched in:
github.com/sipcapture/homer-app 0.0.0-20260625085520-a7d027dc684bConnected by shared product, vendor, weakness, or advisory.
CVE-2026-62252Critical· 9.8Homer is open source telecom observability software
CVE-2026-62253Critical· 9.8Homer is open source telecom observability software
CVE-2025-13263Medium· 6.3A vulnerability was identified in SourceCodester Online Magazine Management System 1.0
CVE-2025-11611Medium· 6.3A weakness has been identified in SourceCodester Simple Inventory System 1.0
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0
CVE-2025-13289Medium· 6.3A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0