High severity8.1GHSA Advisory· Published Oct 7, 2026
CVE-2026-62251
CVE-2026-62251
Description
Homer is open source telecom observability software. Prior to version 11.0.283, the V4StatisticsQuery handler passes the user-supplied rawquery field directly to DuckDB without calling the sqlvalidator.ValidateRawSQL function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue.
Affected products
2- Range: < 0.0.0-20260625085520-a7d027dc684b
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.