Incorrect behavior order in Directus - #VU141288
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect behavior order in FlowsService.deleteMany when handling a DELETE request for a flow. A remote attacker can send a specially crafted request referencing a known flow UUID to cause a denial of service.
Webhook-trigger flow UUIDs may be exposed in public trigger URLs, and affected flows can appear active while downstream steps no longer run.