THREAT OPS › Threat News › [GHSA] GHSA-xx4j-w367-7247 (high) — djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
[GHSA] GHSA-xx4j-w367-7247 (high) — djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
GHSA-xx4j-w367-7247 Severity: high CVE: CVE-2026-55571
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
### Impact
djust's `LiveViewConsumer` mounts a `LiveView` over a WebSocket. When a view is gated (`login_required` / `permission_required`, or an `on_mount` hook th
Indicators of compromise
- CVE-2026-55571cve
Original source: https://github.com/advisories/GHSA-xx4j-w367-7247