Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an opt-in middleware that the documented setup omits; the views themselves enforced only `DEBUG`. In the misconfigured-but-documented scenario (DEBUG on, middleware not installed) a non-localhost client could read live application state and invoke handlers remotely. This issue is fixed in djust 1.0.7. The localhost restriction is enforced in-view on every observability endpoint (no longer dependent on a separately-installed middleware), and `eval_handler` is restricted; gated requests receive a non-disclosing response. As a workaround, ensure `DEBUG=False` in production, and do not expose the observability endpoints to untrusted networks.
Published: 2026-09-16
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

Observability endpoints in djust expose session and view state and provide a remote evaluation surface named eval_handler. The default configuration only enforces the DEBUG flag, while the localhost restriction is implemented by an optional middleware that is omitted from the documentation. When DEBUG is enabled and the middleware is absent, any external client can access these endpoints and invoke handlers remotely, potentially executing arbitrary code. This flaw corresponds to missing authentication for an API (CWE‑306) and improper permission management (CWE‑668).

Affected Systems

djust, released by djust‑org, is vulnerable in all versions before 1.0.7. The patch introduced in version 1.0.7 removes the dependency on the opt‑in middleware, enforces localhost checks within the view logic, and blocks eval_handler unless the request originates locally.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.4, indicating high severity. The EPSS score is below 1 %, suggesting that exploitation is uncommon but still possible. The flaw is not yet listed in CISA’s KEV catalog. An attacker who can reach the observability endpoints from an untrusted network can read application state and invoke eval_handler. If the evaluated handler executes code, this results in remote code execution. Because the endpoints are only protected when DEBUG is disabled or the optional middleware is installed, a misconfigured production deployment is the most realistic attack scenario. The risk is therefore moderate to high, especially for services that expose these endpoints to the public internet.

Generated by OpenCVE AI on September 18, 2026 at 03:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade djust to version 1.0.7 or later.
  • Disable DEBUG mode in production by setting DEBUG=False.
  • Ensure that observability endpoints are not publicly reachable, for example by restricting access through firewall rules or reverse‑proxy configuration.

Generated by OpenCVE AI on September 18, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8g2f-g3gq-5rjv djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
History

Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an opt-in middleware that the documented setup omits; the views themselves enforced only `DEBUG`. In the misconfigured-but-documented scenario (DEBUG on, middleware not installed) a non-localhost client could read live application state and invoke handlers remotely. This issue is fixed in djust 1.0.7. The localhost restriction is enforced in-view on every observability endpoint (no longer dependent on a separately-installed middleware), and `eval_handler` is restricted; gated requests receive a non-disclosing response. As a workaround, ensure `DEBUG=False` in production, and do not expose the observability endpoints to untrusted networks.
Title djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
Weaknesses CWE-306
CWE-668
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:49:45.947Z

Reserved: 2026-07-10T17:12:17.237Z

Link: CVE-2026-61590

cve-icon Vulnrichment

Updated: 2026-09-16T15:49:39.467Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T14:17:06.670

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-668

    Exposure of Resource to Wrong Sphere