GHSA-v9rj-xjfv-xj9r

Suggest an improvement
Source
https://github.com/advisories/GHSA-v9rj-xjfv-xj9r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-v9rj-xjfv-xj9r/GHSA-v9rj-xjfv-xj9r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v9rj-xjfv-xj9r
Aliases
Published
2026-09-16T22:07:52Z
Modified
2026-09-16T22:15:26Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
Details

Impact

The WebSocket handle_mount and ViewRuntime._build_request rebuild an HttpRequest via RequestFactory().get(...) with no HTTP_HOST, so request.get_host() defaulted to "testserver" on the live path. Host/subdomain/domain TenantResolvers then misresolved the tenant — None on the live path while the HTTP path resolved correctly. With STRICT_MODE=False the tenant-scoped managers returned unscoped rows (cross-tenant disclosure); with the default they returned an empty queryset (broken tenancy).

Patches

Fixed in djust 1.0.7. The handshake Host is extracted from the ASGI scope, validated against ALLOWED_HOSTS (the same logic as the CSWSH Origin gate, parsed with Django's split_domain_port so malformed Hosts are rejected at the boundary), and propagated — with the TLS scheme — into the reconstructed request, so live-path tenant resolution matches HTTP exactly.

Workarounds

No workaround on the live path short of upgrading. Most exposed when combined with STRICT_MODE=False.

Database specific
{
    "cwe_ids":  [
        "CWE-348",
        "CWE-639"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-16T22:07:52Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / djust

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.7

Affected versions

0.*
0.1.0
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.9.0
0.9.1
0.9.2
0.9.4
0.9.5
0.9.6
0.9.7
1.*
1.0.0rc1
1.0.0rc2
1.0.0rc3
1.0.0rc4
1.0.0rc6
1.0.0rc7
1.0.0rc8
1.0.0rc9
1.0.0rc10
1.0.0rc11
1.0.0rc12
1.0.0rc13
1.0.0rc14
1.0.0rc15
1.0.0rc16
1.0.0rc17
1.0.0rc18
1.0.0
1.0.1rc1
1.0.1
1.0.2rc1
1.0.2rc2
1.0.2rc3
1.0.2
1.0.3rc1
1.0.3rc2
1.0.3
1.0.4rc1
1.0.4
1.0.5rc1
1.0.5rc2
1.0.5rc3
1.0.5rc4
1.0.5rc5
1.0.5
1.0.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-v9rj-xjfv-xj9r/GHSA-v9rj-xjfv-xj9r.json"