PT-2026-105800 · Pypi · Djust
Published
2026-10-01
·
Updated
2026-10-01
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Impact
SSE sessions were keyed solely by a client-chosen
session id with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a session id could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state.Patches
Fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal.
Workarounds
Disable the SSE transport short of upgrading.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Djust