THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xhhm-f6hp-2qwj (critical) — djust has an authorization bypass on the WebSocket/SSE mount path

[GHSA] GHSA-xhhm-f6hp-2qwj (critical) — djust has an authorization bypass on the WebSocket/SSE mount path

medgithub_advisoriesPublished 2026-09-16

GHSA-xhhm-f6hp-2qwj Severity: critical CVE: CVE-2026-61594

djust has an authorization bypass on the WebSocket/SSE mount path

### Impact The live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required,

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xhhm-f6hp-2qwj