THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f795-p5jw-j6g2 (high) — djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

[GHSA] GHSA-f795-p5jw-j6g2 (high) — djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

medgithub_advisoriesPublished 2026-09-16

GHSA-f795-p5jw-j6g2 Severity: high CVE: CVE-2026-61592

djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

### Impact SSE sessions were keyed solely by a **client-chosen** `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacke

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f795-p5jw-j6g2