Uncaught Exception in Directus - CVE-2023-45820
Published: October 19, 2023 / Updated: April 23, 2026
Directus
Directus
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper exception handling in the websocket server when processing an invalid websocket frame. A remote attacker can send a specially crafted invalid websocket frame to cause a denial of service.
Only installations with websockets enabled are vulnerable.