THREAT OPS › Threat News › [GHSA] GHSA-v9rj-xjfv-xj9r (medium) — djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
[GHSA] GHSA-v9rj-xjfv-xj9r (medium) — djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
GHSA-v9rj-xjfv-xj9r Severity: medium CVE: CVE-2026-61589
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
### Impact The WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(...)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"
Indicators of compromise
- CVE-2026-61589cve
Original source: https://github.com/advisories/GHSA-v9rj-xjfv-xj9r