HIGH
directus
CVE published 2026-07-15
CVE-2026-61835
CVE-2026-61835 is a high-severity vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. The SSRF protection can be bypassed using the address 0.0.0.0, allowing an authenticated user with file-upload rights to fetch internal services. The issue is fixed in version 12.0.0. Defenders should prioritize remediation and review affected scope.