OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-61595: djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data

GitHub Advisories · officialPublished Sep 16, 2026Risk 37/100

### Impact `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and every event handler — and the tenant-aware `QuerySet` manager failed **OPEN** (returned the unfiltered queryset, ignoring `STRICT_MODE`), disclosing **every** tenant's rows to whoever held the socket. `threading.local` was additionally shared across connections on the `sync_to_async` executor thread. ### Patches Fixed in **djust 1.0.7**. Tenant storage moved to a `contextvars.ContextVar` (per async task); the resolved tenant is bound around WS/SSE mount and every dispatch; both managers scope the base queryset once and fail **CLOSED** (`.none()` under the default `STRICT_MODE`); and system check **S006** warns when `STRICT_MODE=False`. ### Workarounds No workaround on the live path short of upgrading.

Upgrade affected packages to a patched version: djust 1.0.7.

Vendor
Not specified
Product
djust
Exploitation
none known
Evidence
official
CVSS
7.7

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source