CVE-2026-61595
Published:September 16, 2026
Updated:October 09, 2026
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, "djust.tenants" isolation was enforced only on the HTTP path. The current tenant was stored in "threading.local()" and set exclusively by the HTTP-only "TenantMiddleware", so on the live (WebSocket/SSE) path "get_current_tenant()" was always "None" during mount and every event handler — and the tenant-aware "QuerySet" manager failed OPEN (returned the unfiltered queryset, ignoring "STRICT_MODE"), disclosing every tenant's rows to whoever held the socket. "threading.local" was additionally shared across connections on the "sync_to_async" executor thread. This issue is fixed in djust 1.0.7. Tenant storage moved to a "contextvars.ContextVar" (per async task); the resolved tenant is bound around WS/SSE mount and every dispatch; both managers scope the base queryset once and fail CLOSED (".none()" under the default "STRICT_MODE"); and system check S006 warns when "STRICT_MODE=False". No known workarounds are available on the live path.
Affected Packages
https://github.com/djust-org/djust.git (GITHUB):
Affected version(s) >=v0.5.0rc1 <v1.0.7Fix Suggestion:
Update to version v1.0.7djust (PYTHON):
Affected version(s) >=0.1.0 <1.0.7Fix Suggestion:
Update to version 1.0.7Related Resources (7)
Do you need more information?
Contact UsCVSS v4
Base Score:
8.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
HIGH
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.7
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
EPSS
Base Score:
0.39