Disclosure summary
### Summary Both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are completely unauthenticated. ### Details **`coordinator/handlers/auth.go` lines 298-304:** ```go func (h *Auth) JWTMiddleware() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // bypass — no validation performed } ``` **`coordinator/handlers/auth_v4_helpers.go` lines 177-182:** ```go func (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc { return func(next echo.HandlerFunc) echo.HandlerFunc { return func(c echo.Context) error { if h.jwtSecret == "" { return next(c) // same bypass ``` **`coordinator/coordinator.go` lines 315-317:** ```go if c.config.JWT.Secret != "" { protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty } ``` **`config/config.go` line 845:** `Secret` field struct tag has `default:""`. The example config ships a placeholder value, but the Go struct de
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-rqcc-94gv-wjm9
Open original source · Updated Oct 07, 2026
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/sipcapture/homer-app | < 0.0.0-20260625093330-5e90809657c9 | 0.0.0-20260625093330-5e90809657c9 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:11:58-04:00
MODIFIED 2026-10-07T12:11:59-04:00
INGESTED 2026-10-08T12:05:11-04:00