THREAT OPS › Threat News › [GHSA] GHSA-8g2f-g3gq-5rjv (high) — djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
[GHSA] GHSA-8g2f-g3gq-5rjv (high) — djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
GHSA-8g2f-g3gq-5rjv Severity: high CVE: CVE-2026-61590
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
### Impact djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an **opt-in middleware that the docume
Indicators of compromise
- CVE-2026-61590cve
Original source: https://github.com/advisories/GHSA-8g2f-g3gq-5rjv