Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: directus Clear
ID Title
CVE-2026-61835 SSRF (Server-Side Request Forgery) in directus (CVE-2026-61835)
SSRF in directus (CVE-2026-61835). Confidential information can be exposed externally. Exploitable via ``IMPORT_IP_DENY_LIST``. Mitigation: upgrade to `12.0.0` or later.
CVE-2026-61836 Vulnerability in directus (CVE-2026-61836)
vulnerability in directus (CVE-2026-61836). Confidential information can be exposed externally. Exploitable via ``version``. Mitigation: upgrade to `12.0.0` or later.
CVE-2026-35410 Vulnerability in monospace (CVE-2026-35410)
vulnerability in monospace (CVE-2026-35410). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.16.1` or later.
CVE-2026-35411 Open Redirect in monospace (CVE-2026-35411)
vulnerability in monospace (CVE-2026-35411). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.16.1` or later.
CVE-2026-35412 Authorization Flaw in monospace (CVE-2026-35412)
vulnerability in monospace (CVE-2026-35412). Data can be tampered with by attackers. Mitigation: upgrade to `11.16.1` or later.
CVE-2026-35413 Information Disclosure in monospace (CVE-2026-35413)
vulnerability in monospace (CVE-2026-35413). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.16.1` or later.
CVE-2026-35441 Vulnerability in monospace (CVE-2026-35441)
vulnerability in monospace (CVE-2026-35441). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.17.0` or later.
CVE-2026-35442 Information Disclosure in monospace (CVE-2026-35442)
vulnerability in monospace (CVE-2026-35442). Confidential information can be exposed externally. Mitigation: upgrade to `11.17.0` or later.
CVE-2026-35408 Vulnerability in monospace (CVE-2026-35408)
vulnerability in monospace (CVE-2026-35408). Confidential information can be exposed externally. Mitigation: upgrade to `11.17.0` or later.
CVE-2026-35409 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-35409)
SSRF in ssrf (CVE-2026-35409). Confidential information can be exposed externally. Mitigation: upgrade to `11.16.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →