PT-2026-30326 · Directus · Directus
Alissonbezerra
+1
·
Published
2026-04-04
·
Updated
2026-04-06
·
CVE-2026-35409
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Directus versions prior to 11.16.0
Description
A Server-Side Request Forgery (SSRF) protection bypass exists in Directus. The IP address validation used to block requests to local and private networks could be circumvented using IPv4-Mapped IPv6 address notation. The validation logic failed to normalize IPv4-Mapped IPv6 addresses before checking them against the deny-list, allowing an attacker to bypass the restriction. This could allow an authenticated user (or an unauthenticated user if public file-import permissions are enabled) to perform SSRF attacks against internal services or cloud instance metadata endpoints.
Recommendations
Update to version 11.16.0 or later.
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Directus