PT-2026-105800 · Pypi · Djust

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Impact

SSE sessions were keyed solely by a client-chosen session id with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a session id could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state.

Patches

Fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal.

Workarounds

Disable the SSE transport short of upgrading.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-4043

Affected Products

Djust