CVE-2026-62253Critical· 9.8▾ MidnightHomer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empt…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated. Version 11.0.283 patches the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/sipcapture/homer-app < 0.0.0-20260625093330-5e90809657c9Patched in:
github.com/sipcapture/homer-app 0.0.0-20260625093330-5e90809657c9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-62252Critical· 9.8Homer is open source telecom observability software
CVE-2026-62251High· 8.1Homer is open source telecom observability software
CVE-2025-9815High· 7.8A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS
CVE-2025-0108Critical· 9.1An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…
CVE-2019-1895Critical· 9.8A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative …
CVE-2026-2603High· 8.1A flaw was found in Keycloak