๐Ÿ” CVE Alert

CVE-2026-62251

HIGH 8.1

Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue.

CWE CWE-89
Vendor sipcapture
Product homer
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for sipcapture homer

Be the first to know when new high vulnerabilities affecting sipcapture homer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

sipcapture / homer
< 11.0.283

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sipcapture/homer/security/advisories/GHSA-f46q-3v67-fmm4 github.com: https://github.com/sipcapture/homer/pull/837 github.com: https://github.com/sipcapture/homer/commit/a7d027dc684b210b62285c49f555ac88d64f35f0 github.com: https://github.com/sipcapture/homer/releases/tag/11.0.283