VYPR
High severity8.1GHSA Advisory· Published Oct 7, 2026

CVE-2026-62251

CVE-2026-62251

Description

Homer is open source telecom observability software. Prior to version 11.0.283, the V4StatisticsQuery handler passes the user-supplied rawquery field directly to DuckDB without calling the sqlvalidator.ValidateRawSQL function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue.

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.