PT-2026-105800 · Pypi · Djust

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Impact

SSE sessions were keyed solely by a client-chosen session id with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a session id could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state.

Patches

Fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal.

Workarounds

Disable the SSE transport short of upgrading.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-4043

Produtos afetados

Djust