Allocation of Resources Without Limits or Throttling in Directus - #VU141293
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the GraphQL WebSocket endpoint when processing GraphQL query and mutation documents over WebSocket transport. A remote user can send a deeply nested crafted GraphQL document to cause a denial of service.
Only instances with WebSockets enabled, GraphQL over WebSockets enabled, and a reachable WebSocket GraphQL endpoint are vulnerable. Amplification depends on user-defined collections with cyclic or self-referencing relations.