Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f46q-3v67-fmm4 | Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query |
Wed, 07 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Homer is open source telecom observability software. Prior to version 11.0.283, the `V4StatisticsQuery` handler passes the user-supplied `rawquery` field directly to DuckDB without calling the `sqlvalidator.ValidateRawSQL` function used throughout the rest of the codebase. Any authenticated user can execute arbitrary SQL statements against all data accessible through the FlightSQL service. Version 11.0.283 patches the issue. | |
| Title | Homer: Authenticated SQL Injection via Unvalidated rawquery Field in /api/v4/statistics/query | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T16:09:41.434Z
Reserved: 2026-07-13T17:09:57.573Z
Link: CVE-2026-62251
No data.
Status : Received
Published: 2026-10-07T17:16:56.303
Modified: 2026-10-07T17:16:56.303
Link: CVE-2026-62251
No data.
OpenCVE Enrichment
Updated: 2026-10-07T18:30:14Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Github GHSA