Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35409

29
FAUCET Score

OVERVIEW CVE-2026-35409 is a Server-Side Request Forgery (SSRF) protection bypass vulnerability affecting Directus, a real-time API and dashboard application for managing SQL database content. Versions prior to 11.16.0 are impacted. The vulnerability exists in the IP address validation mechanism that is designed to block requests to local and private networks; attackers can circumvent this protection by using IPv4-mapped IPv6 address notation to access restricted resources. SEVERITY The vulnerability carries a CVSS score of 7.7 (HIGH) with a network-based attack vector requiring low complexity and authenticated access. The attack requires valid user credentials but no user interaction. The impact is significant, with high confidentiality consequences and the ability to affect resources beyond the vulnerable component itself. The EPSS score of 0.00012 indicates minimal current prevalence among all disclosed vulnerabilities. EXPLOITATION STATUS No active exploitation has been reported. The vulnerability is not present on the CISA Known Exploited Vulnerabilities (KEV) list, and it is marked as inactive on the Hot List, suggesting limited community attention and no publicly available proof-of-concept exploits at this time. Organizations should prioritize updating to version 11.16.0 or later as part of routine patch management, though the current threat level appears low.

Impacted Technologies

VendorProductVersion(s)CPE
< 11.16.0CPE matchmatch criteria
cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 14th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

npmpatch availablevia ghsa
Product: directusFixed in: 11.16.0
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-wv3h-5fx7-966hhigh

Directus: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import

Apr 4, 2026

References

github.com / directus/directus/security/advisories/GHSA-wv3h-5fx7-966h
Vendor Advisory