PT-2026-94118 · Pypi · Djust

CVE-2026-61589

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.7
Description The WebSocket handle mount function and ViewRuntime. build request method rebuild an HttpRequest using RequestFactory().get(...) without including the HTTP HOST. This causes request.get host() to default to "testserver" on the live path, leading TenantResolvers based on host, subdomain, or domain to misresolve the tenant as None. When STRICT MODE is set to False, tenant-scoped managers may return unscoped rows, resulting in cross-tenant disclosure. By default, this issue leads to broken tenancy where an empty queryset is returned.
Recommendations Update djust to version 1.0.7.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61589
GHSA-V9RJ-XJFV-XJ9R

Affected Products

Djust