OVERVIEW CVE-2026-35441 affects Directus versions prior to 11.17.0 and impacts the GraphQL API endpoints (/graphql and /graphql/system). The vulnerability stems from insufficient deduplication of resolver invocations within single GraphQL requests. An authenticated attacker can exploit GraphQL aliasing to artificially amplify expensive relational queries, forcing the server to execute numerous independent complex database operations concurrently. SEVERITY This vulnerability carries a CVSS 3.1 score of 6.5 (Medium), with a network-based attack vector requiring low complexity and low-level authentication privileges. The impact is primarily availability-focused, with potential for high service disruption. The attack is particularly dangerous because rate limiting is disabled by default in Directus deployments, removing a natural throttle against resource exhaustion. Even users with minimal read-only permissions can trigger the condition, causing CPU, memory, and I/O exhaustion that could degrade or completely crash the service. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild, as this vulnerability is not included on the CISA Known Exploited Vulnerabilities (KEV) list and remains inactive on threat monitoring hotlists. The EPSS score of 0.00013 indicates minimal predicted exploitation probability. However, the technical simplicity of the attack—requiring only GraphQL aliasing knowledge and authenticated access—suggests a relatively low barrier to weaponization if awareness increases within the threat community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.17.0CPE matchmatch criteria | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.