These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-10716 is an authenticated SQL injection vulnerability in Directus when using PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with 'geometry' but contains attacker-controlled SQL syntax after the geometry subtype. This issue affects Directus versions before 12.1.0. Administrators and users of Directus instances with P [truncated]
CVE-2026-61836 is a high-severity vulnerability in Directus API versions prior to 12.0.0. The cache-key derivation flaw allows different shares or anonymous clients to receive permission-filtered cached responses without proper re-evaluation. This issue is fixed in version 12.0.0. Affected product deployments may be vulnerable to unauthorized access to cached responses. Users should review and update cach [truncated]
CVE-2026-61835 is a high-severity vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. The SSRF protection can be bypassed using the address 0.0.0.0, allowing an authenticated user with file-upload rights to fetch internal services. The issue is fixed in version 12.0.0. Defenders should prioritize remediation and review affected scope.
CVE-2026-35442 is a high-severity vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. Prior to version 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values instead of the masked placeholder. When combined with groupBy, any authenticated user with read access to the affected collection can [truncated]
CVE-2026-35441 is a denial of service vulnerability in Directus GraphQL API. An authenticated user could exploit GraphQL aliasing to repeat an expensive relational query many times in a single request, forcing the server to execute a large number of independent complex database queries concurrently. This could lead to significant resource exhaustion, potentially degrading or crashing the service. The vuln [truncated]
CVE-2026-35413 is a vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. Prior to version 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus incorrectly exposes schema structure to unauthenticated users at the public permission level and to authenticated users at their permitted permission level via the /graphql/system endpoint. This issue is fixed [truncated]
CVE-2026-35411 is an open redirect vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. Prior to version 11.16.1, an administrator who has not yet configured Two-Factor Authentication (2FA) is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. This vulnerability could be used in phishing attacks targeting Directus admini [truncated]
CVE-2026-35410 is an open redirect vulnerability in Directus, a real-time API and App dashboard for managing SQL database content. The vulnerability allows an attacker to redirect users to arbitrary external domains upon successful authentication. This issue was fixed in version 11.16.1. The vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. The isLoginRedirectAllowed function in [truncated]
Directus, a real-time API and App dashboard for managing SQL database content, had a Server-Side Request Forgery (SSRF) protection bypass vulnerability. This issue, fixed in version 11.16.0, allowed attackers to circumvent IP address validation mechanisms using IPv4-Mapped IPv6 address notation. The vulnerability has a CVSS score of 7.7 and is classified as HIGH severity. Administrators and users of Direc [truncated]
A high-severity vulnerability was discovered in Directus, a real-time API and App dashboard for managing SQL database content. The vulnerability, tracked as CVE-2026-35408, affects Directus versions prior to 11.17.0. It stems from the lack of a Cross-Origin-Opener-Policy (COOP) HTTP response header on the SSO login pages, allowing a malicious cross-origin window to access and manipulate the window object [truncated]