djust has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 7.9 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.9
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-61593High· 8.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance45CVE-2026-55571High· 8.2djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticate…45CVE-2026-61595High· 7.7djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance42GHSA-xjw9-38cr-6372Highdjust: A template binding inherits a context safety grant it never earned (XSS)41GHSA-9395-2g46-rj3fHighdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)41
djust vulnerabilities
CVEs affecting djust, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
GHSA-xjw9-38cr-6372Highdjust: A template binding inherits a context safety grant it never earned (XSS)
djust: A template binding inherits a context safety grant it never earned (XSS)
GHSA-9395-2g46-rj3fHighdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
CVE-2026-61595High· 7.7djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…
CVE-2026-61593High· 8.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin …
CVE-2026-61598High· 7.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is …
CVE-2026-55571High· 8.2djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticate…
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls