THREAT OPS › Threat News › [GHSA] GHSA-f795-p5jw-j6g2 (high) — djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
[GHSA] GHSA-f795-p5jw-j6g2 (high) — djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
GHSA-f795-p5jw-j6g2 Severity: high CVE: CVE-2026-61592
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
### Impact SSE sessions were keyed solely by a **client-chosen** `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacke
Indicators of compromise
- CVE-2026-61592cve
Original source: https://github.com/advisories/GHSA-f795-p5jw-j6g2