CVE-2026-62253

Source
https://cve.org/CVERecord?id=CVE-2026-62253
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62253.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-62253
Aliases
Published
2026-10-07T16:11:00Z
Modified
2026-10-08T02:51:36Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Details

Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated. Version 11.0.283 patches the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62253.json"
}
References

Affected packages

Git / github.com/sipcapture/homer

Affected ranges

Type
GIT
Repo
https://github.com/sipcapture/homer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "11.0.283"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

11.*
11.0.199
11.0.202
11.0.203
11.0.204
11.0.205
11.0.207
11.0.208
11.0.209
11.0.210
11.0.213
11.0.214
11.0.215
11.0.216
11.0.217
11.0.219
11.0.220
11.0.222
11.0.224
11.0.225
11.0.226
11.0.227
11.0.228
11.0.229
11.0.230
11.0.231
11.0.232
11.0.234
11.0.235
11.0.236
11.0.238
11.0.239
11.0.241
11.0.242
11.0.244
11.0.245
11.0.246
11.0.249
11.0.250
11.0.251
11.0.256
11.0.258
11.0.269
11.0.270
11.0.272
11.0.273
11.0.274
11.0.275
11.0.277
11.0.278
11.0.280
11.0.281

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62253.json"