THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8g2f-g3gq-5rjv (high) — djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

[GHSA] GHSA-8g2f-g3gq-5rjv (high) — djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

medgithub_advisoriesPublished 2026-09-16

GHSA-8g2f-g3gq-5rjv Severity: high CVE: CVE-2026-61590

djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

### Impact djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an **opt-in middleware that the docume

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8g2f-g3gq-5rjv