External risk intelligence

Djust WebSocket Authorization Bypass Allows Anonymous Access

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-61594

The vulnerability exists in a web application framework component responsible for server-side rendering and WebSocket communication. Web applications and their associated WebSocket endpoints are commonly deployed as public-facing services, making this surface frequently reachable from the internet in standard production environments.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability was identified in a web framework component that handles server-side rendering and real-time communication. While initial access controls were applied, subsequent real-time interactions over WebSockets bypassed these protections, potentially allowing unauthorized access to view and manipulate data. This issue has been addressed in version 1.0.7 of the framework.

  • Unauthorized real-time data access possible.
  • Impacts server-side rendering and live data.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could bypass standard Django authorization checks by opening a WebSocket connection. This allows them to interact with views, including administrative functions, as if they were authenticated, even without logging in.

  • Unauthenticated access to a web application.
  • Opening a WebSocket connection to a vulnerable view.
  • Unauthorized access to sensitive data and actions.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an anonymous or unauthorized user could bypass Django's authorization checks by establishing a WebSocket connection to a view. This could allow them to interact with sensitive application functionality that should be restricted.

  • Access to restricted views and data.
  • Bypassed authorization over WebSockets.
  • Unauthorized actions on application data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The djust package's authorization bypass vulnerability impacts Django applications using its LiveView-style rendering. Application owners and platform teams are likely responsible for identifying and remediating this issue, as it affects how server-side logic handles client interactions. The first practical step involves locating all djust deployments, assessing their reachability and criticality, and then coordinating remediation with the responsible parties.

  • Application owners should own the issue.
  • Verify reachability and impact of deployments.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the djust software component?

djust is a framework that brings reactive, server-side rendering—similar to Phoenix LiveView—to Django applications. It uses Rust to power real-time updates over WebSocket connections, allowing developers to build dynamic user interfaces that respond instantly to events without requiring full page reloads.

How does CVE-2026-61594 create a security gap?

This vulnerability involves Missing Authentication for Critical Function (CWE-306) and Missing Authorization (CWE-862). While djust correctly verified credentials during the initial HTTP request, it failed to re-verify them when transitioning to the persistent WebSocket connection. This allowed unauthorized users to interact with protected views as if they were fully authenticated.

Do I need to be logged in to trigger this bug?

No. The flaw specifically allows anonymous or under-privileged users to establish a WebSocket connection and mount sensitive views. You do not need existing credentials to exploit the bypass, as the vulnerable WebSocket transport relies on a separate authorization check that does not honor standard Django security mixins.

How do I know if my system is at risk?

According to Halo Surface Signal, this vulnerability affects web applications where WebSocket endpoints are exposed. Because these components are typically deployed as public-facing services, your application is likely reachable from the internet, increasing the probability that an unauthorized user could access restricted administrative or data-heavy views.

Is there a fix for this authorization issue?

Yes. You must update to djust version 1.0.7 or later, which ensures authorization logic is applied consistently across all transports. If you cannot update immediately, migrate away from HTTP-only mixins and decorators to djust-native authorization attributes, which are explicitly designed to be honored during WebSocket communication.

References