Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and every event handler — and the tenant-aware `QuerySet` manager failed OPEN (returned the unfiltered queryset, ignoring `STRICT_MODE`), disclosing every tenant's rows to whoever held the socket. `threading.local` was additionally shared across connections on the `sync_to_async` executor thread. This issue is fixed in djust 1.0.7. Tenant storage moved to a `contextvars.ContextVar` (per async task); the resolved tenant is bound around WS/SSE mount and every dispatch; both managers scope the base queryset once and fail CLOSED (`.none()` under the default `STRICT_MODE`); and system check S006 warns when `STRICT_MODE=False`. No known workarounds are available on the live path.
Published: 2026-09-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Exposure
Action: Immediate Patch
AI Analysis

Impact

Prior to version 1.0.7 djust, a Python framework for reactive server‑side rendering, stored the current tenant in a thread‑local variable set only by HTTP middleware. When a WebSocket or Server‑Sent Events connection was opened, the tenant value was None, causing the tenant‑aware QuerySet manager to operate in an unrestricted mode and return unfiltered data. This flaw allows any user who can open a WebSocket/SSE link to read rows belonging to all tenants, effectively bypassing tenant isolation and exposing sensitive data across the entire application.

Affected Systems

djust-org’s djust library, any release prior to 1.0.7. The vulnerability is fixed in version 1.0.7 and later; any Django project using the library with WebSocket or SSE endpoints prior to that upgrade is affected.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation currently, and the issue is not listed in CISA KEV. Exploitation requires the attacker to open a WebSocket or SSE connection to the application; because the tenant context is missing, the ORM returns all rows, disclosing every tenant’s data. No workaround exists for the live (WebSocket/SSE) path. Maintaining STRICT_MODE and enabling the system check S006 helps detect mis‑configurations and mitigate risk.

Generated by OpenCVE AI on September 18, 2026 at 01:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade djust to version 1.0.7 or later.
  • Ensure the STRICT_MODE setting is enabled; this regular expression guards against accidental OPEN behavior.
  • Run Django system checks, including S006, to detect missing tenant context configurations.

Generated by OpenCVE AI on September 18, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3492-cvg7-9mr2 djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
History

Fri, 18 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and every event handler — and the tenant-aware `QuerySet` manager failed OPEN (returned the unfiltered queryset, ignoring `STRICT_MODE`), disclosing every tenant's rows to whoever held the socket. `threading.local` was additionally shared across connections on the `sync_to_async` executor thread. This issue is fixed in djust 1.0.7. Tenant storage moved to a `contextvars.ContextVar` (per async task); the resolved tenant is bound around WS/SSE mount and every dispatch; both managers scope the base queryset once and fail CLOSED (`.none()` under the default `STRICT_MODE`); and system check S006 warns when `STRICT_MODE=False`. No known workarounds are available on the live path.
Title djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
Weaknesses CWE-636
CWE-862
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:35:16.208Z

Reserved: 2026-07-10T17:12:17.238Z

Link: CVE-2026-61595

cve-icon Vulnrichment

Updated: 2026-09-16T18:18:45.442Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T16:17:14.080

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:15:06Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')

  • CWE-862

    Missing Authorization