THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v9rj-xjfv-xj9r (medium) — djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

[GHSA] GHSA-v9rj-xjfv-xj9r (medium) — djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

medgithub_advisoriesPublished 2026-09-16

GHSA-v9rj-xjfv-xj9r Severity: medium CVE: CVE-2026-61589

djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

### Impact The WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(...)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v9rj-xjfv-xj9r