PatchSiren

Directus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Directus CVE published 2026-08-05

CVE-2026-10716

CVE-2026-10716 is an authenticated SQL injection vulnerability in Directus when using PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with 'geometry' but contains attacker-controlled SQL syntax after the geometry subtype. This issue affects Directus versions before 12.1.0. Administrators and users of Directus instances with P [truncated]

HIGH directus CVE published 2026-07-15

CVE-2026-61836

CVE-2026-61836 is a high-severity vulnerability in Directus API versions prior to 12.0.0. The cache-key derivation flaw allows different shares or anonymous clients to receive permission-filtered cached responses without proper re-evaluation. This issue is fixed in version 12.0.0. Affected product deployments may be vulnerable to unauthorized access to cached responses. Users should review and update cach [truncated]

HIGH directus CVE published 2026-07-15

CVE-2026-61835

CVE-2026-61835 is a high-severity vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. The SSRF protection can be bypassed using the address 0.0.0.0, allowing an authenticated user with file-upload rights to fetch internal services. The issue is fixed in version 12.0.0. Defenders should prioritize remediation and review affected scope.

HIGH directus CVE published 2026-04-06

CVE-2026-35442

CVE-2026-35442 is a high-severity vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. Prior to version 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values instead of the masked placeholder. When combined with groupBy, any authenticated user with read access to the affected collection can [truncated]

MEDIUM directus CVE published 2026-04-06

CVE-2026-35441

CVE-2026-35441 is a denial of service vulnerability in Directus GraphQL API. An authenticated user could exploit GraphQL aliasing to repeat an expensive relational query many times in a single request, forcing the server to execute a large number of independent complex database queries concurrently. This could lead to significant resource exhaustion, potentially degrading or crashing the service. The vuln [truncated]

MEDIUM directus CVE published 2026-04-06

CVE-2026-35413

CVE-2026-35413 is a vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. Prior to version 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus incorrectly exposes schema structure to unauthenticated users at the public permission level and to authenticated users at their permitted permission level via the /graphql/system endpoint. This issue is fixed [truncated]

MEDIUM directus CVE published 2026-04-06

CVE-2026-35411

CVE-2026-35411 is an open redirect vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. Prior to version 11.16.1, an administrator who has not yet configured Two-Factor Authentication (2FA) is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. This vulnerability could be used in phishing attacks targeting Directus admini [truncated]

MEDIUM directus CVE published 2026-04-06

CVE-2026-35410

CVE-2026-35410 is an open redirect vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. The vulnerability allows an attacker to redirect users to arbitrary external domains upon successful authentication. This issue was fixed in version 11.16.1. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. The isLoginRedirectAllowed function in [truncated]

HIGH directus CVE published 2026-04-06

CVE-2026-35409

Directus, a real-time API and App dashboard for managing SQL database content, had a Server-Side Request Forgery (SSRF) protection bypass vulnerability. This issue, fixed in version 11.16.0, allowed attackers to circumvent IP address validation mechanisms using IPv4-Mapped IPv6 address notation. The vulnerability has a CVSS score of 7.7 and is classified as HIGH severity. Administrators and users of Direc [truncated]

HIGH directus CVE published 2026-04-06

CVE-2026-35408

A high-severity vulnerability was discovered in Directus, a real-time API and App dashboard for managing SQL database content. The vulnerability, tracked as CVE-2026-35408, affects Directus versions prior to 11.17.0. It stems from the lack of a Cross-Origin-Opener-Policy (COOP) HTTP response header on the SSO login pages, allowing a malicious cross-origin window to access and manipulate the window object [truncated]