CVE-2026-61590
—Unauthenticated Access to djust Observability Endpoints Exposes Live App State
Observability endpoints in the djust pip package (a Django live-view framework) expose live view/session state and a remote method-invocation surface (`eval_handler`) over the network. The localhost-only restriction was implemented as an opt-in middleware that the documented setup omits, while the endpoint views themselves enforced only the DEBUG flag, so in the documented configuration with DEBUG=True a non-localhost client could reach these endpoints without authentication. An attacker gains disclosure of live application and session state (CWE-668) plus the ability to remotely invoke handlers (CWE-306), yielding both confidentiality and integrity impact. Anyone running djust versions prior to 1.0.7 without the optional middleware and with the observability endpoints reachable from an untrusted network is affected. No public proof-of-concept is known and the flaw is not listed in CISA KEV.
What to do: Upgrade to djust 1.0.7 or later, which enforces the localhost restriction in-view on every observability endpoint and restricts `eval_handler`. Ensure DEBUG=False in production and do not expose the observability endpoints to untrusted networks; check access logs for external requests to these endpoints on pre-1.0.7 deployments.
| djust | All versions prior to 1.0.7 (pip) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an opt-in middleware that the documented setup omits; the views themselves enforced only `DEBUG`. In the misconfigured-but-documented scenario (DEBUG on, middleware not installed) a non-localhost client could read live application state and invoke handlers remotely. This issue is fixed in djust 1.0.7. The localhost restriction is enforced in-view on every observability endpoint (no longer dependent on a separately-installed middleware), and `eval_handler` is restricted; gated requests receive a non-disclosing response. As a workaround, ensure `DEBUG=False` in production, and do not expose the observability endpoints to untrusted networks.
- Ecosystems
- pip
- Weakness
- CWE-306, CWE-668
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- GHSA
- GHSA-8g2f-g3gq-5rjv (high)
In the news0 stories
No ingested article mentions this CVE yet.