Description
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches the issue.
Published: 2026-10-07
Score: 9.8 Critical
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rqcc-94gv-wjm9 Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
History

Wed, 07 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. Version 11.0.283 patches the issue.
Title Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T16:11:00.294Z

Reserved: 2026-07-13T17:09:57.573Z

Link: CVE-2026-62253

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T17:16:56.627

Modified: 2026-10-07T17:16:56.627

Link: CVE-2026-62253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:30:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function