Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f46q-3v67-fmm4 | Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue. | |
| Title | Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T16:09:41.434Z
Reserved: 2026-07-13T17:09:57.573Z
Link: CVE-2026-62251
No data.
Status : Received
Published: 2026-10-07T17:16:56.303
Modified: 2026-10-07T17:16:56.303
Link: CVE-2026-62251
No data.
OpenCVE Enrichment
Updated: 2026-10-07T18:30:14Z
Weaknesses
Github GHSA