Allocation of Resources Without Limits or Throttling in Directus - CVE-2026-35441
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the GraphQL endpoints when processing crafted GraphQL queries with repeated aliases. A remote user can send a specially crafted GraphQL request to cause a denial of service.
Any authenticated user, including one with minimal read-only permissions, can trigger the issue. The impact scales with the number of aliases, relational query depth, and concurrent requests.