Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(...)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"testserver"` on the live path. Host/subdomain/domain `TenantResolver`s then misresolved the tenant — `None` on the live path while the HTTP path resolved correctly. With `STRICT_MODE=False` the tenant-scoped managers returned unscoped rows (cross-tenant disclosure); with the default they returned an empty queryset (broken tenancy). This is fixed in djust 1.0.7. The handshake Host is extracted from the ASGI scope, validated against `ALLOWED_HOSTS` (the same logic as the CSWSH Origin gate, parsed with Django's `split_domain_port` so malformed Hosts are rejected at the boundary), and propagated — with the TLS scheme — into the reconstructed request, so live-path tenant resolution matches HTTP exactly. There is no known workaround on the live path short of upgrading. Users are most exposed when combined with `STRICT_MODE=False`.
Published: 2026-09-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Tenant Disclosure
Action: Apply Patch
AI Analysis

Impact

A vulnerability exists in the WebSocket handling of djust prior to version 1.0.7 where the server rebuilds an HTTP request without including the original client Host. The resulting request defaults to the string "testserver", causing tenant resolution mechanisms that rely on host or subdomain to misidentify the tenant. When tenant resolution fails, the application either returns an empty dataset (broken tenancy) or, if configuration permits, returns unscoped data from other tenants (cross‑tenant disclosure). The flaw therefore directly violates confidentiality and may also impact integrity and availability of data segregation.

Affected Systems

The affected product is djust made by djust‑org. All releases before 1.0.7 are vulnerable, including 1.0.6 and earlier editions. Updating to 1.0.7 or later is required to receive the fix.

Risk and Exploitability

The CVSS score of 6.3 classifies the issue as moderate. The EPSS score falls below 1 %, suggesting exploitation is unlikely yet still possible, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by initiating a WebSocket connection to the live path and relying on the host omission to obtain data from a different tenant or to break tenant isolation. The fix now validates the handshake Host against ALLOWED_HOSTS and propagates it to the reconstructed request, matching live‑path tenant resolution to HTTP. The risk is heightened when STRICT_MODE is disabled, which would allow cross‑tenant data leakage for any existing connections.

Generated by OpenCVE AI on September 18, 2026 at 00:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade djust to version 1.0.7 or later to obtain the host validation and reconstruction fix.
  • If an upgrade cannot be performed immediately, enable STRICT_MODE to prevent unscoped data from being returned on misresolved tenants.
  • Verify that ALLOWED_HOSTS is set to the expected hostnames and that WebSocket connections are required to use TLS so the host validation logic applies.

Generated by OpenCVE AI on September 18, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v9rj-xjfv-xj9r djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
History

Fri, 18 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(...)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"testserver"` on the live path. Host/subdomain/domain `TenantResolver`s then misresolved the tenant — `None` on the live path while the HTTP path resolved correctly. With `STRICT_MODE=False` the tenant-scoped managers returned unscoped rows (cross-tenant disclosure); with the default they returned an empty queryset (broken tenancy). This is fixed in djust 1.0.7. The handshake Host is extracted from the ASGI scope, validated against `ALLOWED_HOSTS` (the same logic as the CSWSH Origin gate, parsed with Django's `split_domain_port` so malformed Hosts are rejected at the boundary), and propagated — with the TLS scheme — into the reconstructed request, so live-path tenant resolution matches HTTP exactly. There is no known workaround on the live path short of upgrading. Users are most exposed when combined with `STRICT_MODE=False`.
Title djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
Weaknesses CWE-348
CWE-639
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:23:05.705Z

Reserved: 2026-07-10T17:12:17.237Z

Link: CVE-2026-61589

cve-icon Vulnrichment

Updated: 2026-09-17T17:10:33.419Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T23:16:53.717

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:45:16Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source

  • CWE-639

    Authorization Bypass Through User-Controlled Key