Observable discrepancy in Directus - CVE-2025-64749
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to observable discrepancy in the Directus REST API /items/{collection} endpoint when handling requests for existing and non-existing collections. A remote user can send a request for a collection name to disclose sensitive information.
Different error messages reveal whether a collection exists even when access to that collection is not authorized.