PatchSiren cyber security CVE debrief
CVE-2026-35409 directus CVE debrief
Directus, a real-time API and App dashboard for managing SQL database content, had a Server-Side Request Forgery (SSRF) protection bypass vulnerability. This issue, fixed in version 11.16.0, allowed attackers to circumvent IP address validation mechanisms using IPv4-Mapped IPv6 address notation. The vulnerability has a CVSS score of 7.7 and is classified as HIGH severity. Administrators and users of Directus versions prior to 11.16.0 should apply the patch to prevent potential SSRF attacks.
- Vendor
- directus
- Product
- Unknown
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Administrators and users of Directus versions prior to 11.16.0 should apply the patch to prevent potential SSRF attacks. This includes reviewing and updating IP address validation mechanisms, monitoring for potential SSRF attacks, and ensuring that the patch is applied to all affected systems.
Technical summary
The Directus SSRF protection bypass vulnerability, tracked as CVE-2026-35409, was caused by a weakness in the IP address validation mechanism. This mechanism could be circumvented using IPv4-Mapped IPv6 address notation, allowing attackers to make requests to local and private networks. The vulnerability had a CVSS score of 7.7 and was classified as HIGH severity. The issue is fixed in Directus version 11.16.0.
Defensive priority
Apply the patch to Directus versions prior to 11.16.0 to prevent potential SSRF attacks. Review and update IP address validation mechanisms, and monitor for potential SSRF attacks.
Recommended defensive actions
- Apply the patch to Directus versions prior to 11.16.0
- Review and update IP address validation mechanisms
- Monitor for potential SSRF attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-06T22:16:21.930Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 7.7 and is classified as HIGH severity. The IP address validation mechanism used to block requests to local and private networks could be circumvented using IPv4-Mapped IPv6 address notation. This issue is fixed in Directus version 11.16.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35409 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35409
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35409 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35409
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/directus/directus/security/advisories/GHSA-wv3h-5fx7-966h
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.