Server-Side Request Forgery (SSRF) in Directus - CVE-2026-35409
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information from internal services.
The vulnerability exists due to improper input validation in the file import functionality when processing user-supplied URLs containing IPv4-mapped IPv6 addresses. A remote user can supply a crafted URL to disclose sensitive information from internal services.
Public file-import permissions can allow exploitation without authentication.