GHSA-rqcc-94gv-wjm9: Critical severity go/github.com/sipcapture/homer-app vulnerability
Summary Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.
Details coordinator/handlers/auth.go lines 298-304: go func (h Auth) JWTMiddleware() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // bypass — no validation performed }
coordinator/handlers/authv4helpers.go lines 177-182: go func (h Auth) JWTMiddlewareV4() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // same bypass
coordinator/coordinator.go lines 315-317: go if c.config.JWT.Secret != "" { protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty }
config/config.go line 845: Secret field struct tag has default:"". The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.
PoC bash On a default Homer installation (no JWT secret configured), all protected routes are open: curl http://<homer-host>/api/v3/users Returns full user list with no credentials
curl http://<homer-host>/api/v3/databases Returns all database connection strings
curl -X POST http://<homer-host>/api/v3/users \ -H 'Content-Type: application/json' \ -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}' Creates a new admin user with no credentials
Impact Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.
Fix Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions: go if h.jwtSecret == "" { log.Fatal("coordinator.jwt.secret must be set to a non-empty value") }
If possible, please apply for a CVE number when posting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/sipcapture/homer-appto a version that resolves this vulnerability.Fixed in 0.0.0-20260625093330-5e90809657c9 - Configuration
Configure JWT.Secret to a strong non-empty value; abort startup with a fatal error if the setting is empty.
Homer coordinator JWT.Secret = strong non-empty secret - Compensating control
Remove the empty-string bypass from both JWTMiddleware and JWTMiddlewareV4 so protected API routes always perform JWT validation, and ensure the authentication middleware is registered even when the secret is empty.
Event History
Frequently Asked Questions
Which deployments are exposed?
Default installations are exposed because the JWT secret defaults to an empty string. Protected endpoints under /api/v1, /api/v3, and /api/v4 are unauthenticated when that secret is empty.
What does an attacker need to exploit this?
An attacker needs only network access to the affected API endpoints. No credentials, valid JWT, user interaction, or special conditions are required.
How can I determine whether my instance is affected?
Check the configured JWT secret. If it is empty or unset, JWT middleware is bypassed and, for the referenced coordinator configuration, is not registered for protected routes.
What can be done if patching cannot happen immediately?
Configure a non-empty JWT secret. The described bypass occurs specifically when the JWT secret is empty.