OVERVIEW CVE-2026-35409 is a Server-Side Request Forgery (SSRF) protection bypass vulnerability affecting Directus, a real-time API and dashboard application for managing SQL database content. Versions prior to 11.16.0 are impacted. The vulnerability exists in the IP address validation mechanism that is designed to block requests to local and private networks; attackers can circumvent this protection by using IPv4-mapped IPv6 address notation to access restricted resources. SEVERITY The vulnerability carries a CVSS score of 7.7 (HIGH) with a network-based attack vector requiring low complexity and authenticated access. The attack requires valid user credentials but no user interaction. The impact is significant, with high confidentiality consequences and the ability to affect resources beyond the vulnerable component itself. The EPSS score of 0.00012 indicates minimal current prevalence among all disclosed vulnerabilities. EXPLOITATION STATUS No active exploitation has been reported. The vulnerability is not present on the CISA Known Exploited Vulnerabilities (KEV) list, and it is marked as inactive on the Hot List, suggesting limited community attention and no publicly available proof-of-concept exploits at this time. Organizations should prioritize updating to version 11.16.0 or later as part of routine patch management, though the current threat level appears low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.16.0CPE matchmatch criteria | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.