djust vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-61599Highdjust: djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount pathCVE-2026-61589Mediumdjust: djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on…CVE-2026-61596Highdjust: djust has broken object-level access control (IDOR)CVE-2026-61588Mediumdjust: djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute…CVE-2026-61594Criticaldjust: djust has an authorization bypass on the WebSocket/SSE mount pathCVE-2026-61591Highdjust: djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)CVE-2026-61592Highdjust: djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session…CVE-2026-61597Mediumdjust: djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tagsCVE-2026-61593Highdjust: djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE sessionCVE-2026-61595Highdjust: djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' dataCVE-2026-61598Highdjust: djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handlerCVE-2026-61590Highdjust: djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only…CVE-2026-55571Highdjust: djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated…

Stop the waste.
Protect your environment with Kodem.