PatchSiren cyber security CVE debrief
CVE-2026-35409 directus CVE debrief
Directus, a real-time API and App dashboard for managing SQL database content, had a Server-Side Request Forgery (SSRF) protection bypass vulnerability. This issue, fixed in version 11.16.0, allowed attackers to circumvent IP address validation mechanisms using IPv4-Mapped IPv6 address notation. The vulnerability has a CVSS score of 7.7 and is classified as HIGH severity. Administrators and users of Directus versions prior to 11.16.0 should apply the patch to prevent potential SSRF attacks.
- Vendor
- directus
- Product
- Unknown
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Administrators and users of Directus versions prior to 11.16.0 should apply the patch to prevent potential SSRF attacks. This includes reviewing and updating IP address validation mechanisms, monitoring for potential SSRF attacks, and ensuring that the patch is applied to all affected systems.
Technical summary
The Directus SSRF protection bypass vulnerability, tracked as CVE-2026-35409, was caused by a weakness in the IP address validation mechanism. This mechanism could be circumvented using IPv4-Mapped IPv6 address notation, allowing attackers to make requests to local and private networks. The vulnerability had a CVSS score of 7.7 and was classified as HIGH severity. The issue is fixed in Directus version 11.16.0.
Defensive priority
Apply the patch to Directus versions prior to 11.16.0 to prevent potential SSRF attacks. Review and update IP address validation mechanisms, and monitor for potential SSRF attacks.
Recommended defensive actions
- Apply the patch to Directus versions prior to 11.16.0
- Review and update IP address validation mechanisms
- Monitor for potential SSRF attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-06T22:16:21.930Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability has a CVSS score of 7.7 and is classified as HIGH severity. The IP address validation mechanism used to block requests to local and private networks could be circumvented using IPv4-Mapped IPv6 address notation. This issue is fixed in Directus version 11.16.0.
Official resources
-
CVE-2026-35409 CVE record
CVE.org
-
CVE-2026-35409 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T22:16:21.930Z and has not been modified since then. The NVD entry is currently Analyzed.