OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-61590: djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

GitHub Advisories · officialPublished Sep 16, 2026Risk 37/100

### Impact djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an **opt-in middleware that the documented setup omits**; the views themselves enforced only `DEBUG`. In the misconfigured-but-documented scenario (DEBUG on, middleware not installed) a non-localhost client could read live application state and invoke handlers remotely. ### Patches Fixed in **djust 1.0.7**. The localhost restriction is enforced **in-view** on every observability endpoint (no longer dependent on a separately-installed middleware), and `eval_handler` is restricted; gated requests receive a non-disclosing response. ### Workarounds Ensure `DEBUG=False` in production, and do not expose the observability endpoints to untrusted networks.

Upgrade affected packages to a patched version: djust 1.0.7.

Vendor
Not specified
Product
djust
Exploitation
none known
Evidence
official
CVSS
7.4

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source