CVE-2026-61589

Source
https://cve.org/CVERecord?id=CVE-2026-61589
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61589.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-61589
Aliases
Published
2026-09-16T22:08:52Z
Modified
2026-09-18T03:48:29Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
Details

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket handle_mount and ViewRuntime._build_request rebuild an HttpRequest via RequestFactory().get(...) with no HTTP_HOST, so request.get_host() defaulted to "testserver" on the live path. Host/subdomain/domain TenantResolvers then misresolved the tenant — None on the live path while the HTTP path resolved correctly. With STRICT_MODE=False the tenant-scoped managers returned unscoped rows (cross-tenant disclosure); with the default they returned an empty queryset (broken tenancy). This is fixed in djust 1.0.7. The handshake Host is extracted from the ASGI scope, validated against ALLOWED_HOSTS (the same logic as the CSWSH Origin gate, parsed with Django's split_domain_port so malformed Hosts are rejected at the boundary), and propagated — with the TLS scheme — into the reconstructed request, so live-path tenant resolution matches HTTP exactly. There is no known workaround on the live path short of upgrading. Users are most exposed when combined with STRICT_MODE=False.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-348",
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61589.json"
}
References

Affected packages

Git / github.com/djust-org/djust

Affected ranges

Type
GIT
Repo
https://github.com/djust-org/djust
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.0.7"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.2.0
v0.2.0a1
v0.2.0a2
v0.2.1
v0.2.1a1
v0.2.2
v0.2.2rc1
v0.2.2rc2
v0.2.2rc3
v0.2.2rc5
v0.3.0
v0.3.0rc1
v0.3.0rc2
v0.3.0rc3
v0.3.0rc4
v0.3.0rc5
v0.3.1
v0.3.2rc1
v0.3.3rc1
v0.3.3rc2
v0.3.3rc3
v0.3.4
v0.3.5
v0.3.5rc1
v0.3.5rc2
v0.3.6
v0.3.6rc1
v0.3.6rc2
v0.3.6rc3
v0.3.6rc4
v0.3.7
v0.3.7rc1
v0.3.7rc2
v0.3.8
v0.3.8rc1
v0.4.0
v0.4.0rc3
v0.4.1
v0.4.1rc1
v0.4.1rc2
v0.4.2
v0.4.2rc1
v0.4.2rc2
v0.4.2rc3
v0.4.2rc4
v0.4.3
v0.4.3rc1
v0.4.4
v0.4.4rc1
v0.4.5rc1
v0.4.5rc2
v0.5.0rc1
v0.5.0rc2
v0.5.1rc1
v0.5.1rc2
v0.5.1rc4
v0.5.2rc1
v0.5.3rc1
v0.5.4rc1
v0.5.5rc1
v0.5.6rc1
v0.5.7rc1
v0.6.0rc1
v0.6.1rc1
v0.7.0rc1
v0.7.1rc1
v0.7.2rc1
v0.7.3rc1
v0.7.4rc1
v0.8.0rc1
v0.8.2rc1
v0.8.3rc1
v0.8.4rc1
v0.8.5rc1
v0.8.6rc1
v0.8.7rc1
v0.8.8rc1
v0.8.8rc2
v0.9.0
v0.9.0rc1
v0.9.0rc2
v0.9.0rc3
v0.9.0rc4
v0.9.0rc5
v0.9.1
v0.9.2
v0.9.2rc1
v0.9.2rc2
v0.9.3rc1
v0.9.3rc2
v0.9.4
v0.9.4rc1
v0.9.4rc2
v0.9.4rc3
v0.9.4rc5
v0.9.4rc6
v0.9.4rc7
v0.9.4rc8
v0.9.4rc9
v0.9.5
v0.9.5rc1
v0.9.5rc2
v0.9.5rc3
v0.9.5rc4
v0.9.6
v0.9.6rc1
v0.9.6rc2
v0.9.6rc3
v0.9.7
v0.9.7rc1
v0.9.7rc2
v0.9.7rc3
v1.*
v1.0.0
v1.0.0rc1
v1.0.0rc10
v1.0.0rc11
v1.0.0rc12
v1.0.0rc13
v1.0.0rc14
v1.0.0rc15
v1.0.0rc16
v1.0.0rc17
v1.0.0rc18
v1.0.0rc2
v1.0.0rc3
v1.0.0rc4
v1.0.0rc6
v1.0.0rc7
v1.0.0rc8
v1.0.0rc9
v1.0.1
v1.0.1rc1
v1.0.2
v1.0.2rc1
v1.0.2rc2
v1.0.2rc3
v1.0.3
v1.0.3rc1
v1.0.3rc2
v1.0.4
v1.0.4rc1
v1.0.5
v1.0.5rc1
v1.0.5rc2
v1.0.5rc3
v1.0.5rc4
v1.0.5rc5
v1.0.6
v1.0.6rc1
v1.0.6rc2
v1.0.6rc3
v1.0.7rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61589.json"