


Perceptive Security
SOC/SIEM Consultancy

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sen…
Published:
25 augustus 2026 om 00:00:00
Alert date:
25 augustus 2026 om 20:05:56
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-55571 affects djust, a Phoenix LiveView-style reactive server-side rendering framework for Django with Rust-powered performance. Prior to version 1.0.4, the LiveViewConsumer.handle_mount method sends a navigate redirect frame when authentication or authorization denies a LiveView mount, but fails to close the WebSocket connection or clear the view instance. A malicious raw WebSocket client can ignore the redirect and retain the mounted socket. Since LiveViewConsumer.handle_event does not recheck authentication or authorization, attackers can send event frames to invoke event handler methods without a valid authenticated session. This flaw enables unauthorized sensitive data reads or mutations, including via handle_live_redirect_mount. The vulnerability has been patched in djust version 1.0.4.
Technical details
Mitigation steps:
Affected products:
djust
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55571
https://github.com/djust-org/djust/commit/1ae8aa9246b80477de7ddc4d90319a3b267bef04
https://github.com/djust-org/djust/pull/1780
https://github.com/djust-org/djust/releases/tag/v1.0.4
https://github.com/djust-org/djust/security/advisories/GHSA-xx4j-w367-7247
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
