PT-2026-30326 · Directus · Directus

Alissonbezerra

+1

·

Published

2026-04-04

·

Updated

2026-04-06

·

CVE-2026-35409

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 11.16.0
Description A Server-Side Request Forgery (SSRF) protection bypass exists in Directus. The IP address validation used to block requests to local and private networks could be circumvented using IPv4-Mapped IPv6 address notation. The validation logic failed to normalize IPv4-Mapped IPv6 addresses before checking them against the deny-list, allowing an attacker to bypass the restriction. This could allow an authenticated user (or an unauthenticated user if public file-import permissions are enabled) to perform SSRF attacks against internal services or cloud instance metadata endpoints.
Recommendations Update to version 11.16.0 or later.

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35409
GHSA-WV3H-5FX7-966H

Affected Products

Directus