CVE-2026-61590: djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
### Impact djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an **opt-in middleware that the documented setup omits**; the views themselves enforced only `DEBUG`. In the misconfigured-but-documented scenario (DEBUG on, middleware not installed) a non-localhost client could read live application state and invoke handlers remotely. ### Patches Fixed in **djust 1.0.7**. The localhost restriction is enforced **in-view** on every observability endpoint (no longer dependent on a separately-installed middleware), and `eval_handler` is restricted; gated requests receive a non-disclosing response. ### Workarounds Ensure `DEBUG=False` in production, and do not expose the observability endpoints to untrusted networks.
Recommended action
Recommended action
Upgrade affected packages to a patched version: djust 1.0.7.
Technical details
- Vendor
- Not specified
- Product
- djust
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source