github.com/sipcapture/homer-app
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/sipcapture/homer-apppage 1 of 1
- CVE-2026-62251HIGHCVSS 8.1EG 8.1fixed in 0.0.0-20260625085520-a7d027dc684b2026-10-07
Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used th…
- CVE-2026-62252CRITICALCVSS 9.8EG 9.8fixed in 0.0.0-20260625091610-b2e942031ff82026-10-07
Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (s…
- CVE-2026-62253CRITICALCVSS 9.8EG 9.8fixed in 0.0.0-20260625093330-5e90809657c92026-10-07
Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty …
Check whether github.com/sipcapture/homer-app is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/sipcapture/homer-app CVEs against the assets you own.
Book a Demo →