#VU127102 Resource exhaustion in Directus - CVE-2024-39895

 

#VU127102 Resource exhaustion in Directus - CVE-2024-39895

Published: July 8, 2024 / Updated: April 23, 2026


Vulnerability identifier: #VU127102
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-39895
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Directus
Software vendor:
Directus

Description

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the GraphQL endpoint when processing crafted GraphQL queries with duplicated fields. A remote user can send a specially crafted GraphQL query to cause a denial of service.

The issue can cause the service to become unresponsive for several minutes, and repeated requests can keep the service unavailable.


Remediation

Install security update from vendor's website.

External links