Directus Server-Side Request Forgery Protection Bypass Vulnerability

Vulnerability

A Server-Side Request Forgery (SSRF) protection bypass vulnerability has been identified in Directus versions prior to 11.16.0. The issue arises from the IP address validation mechanism, which is intended to block requests to local and private networks. This validation could be circumvented by using IPv4-Mapped IPv6 address notation, allowing authenticated users (or unauthenticated users with public file-import permissions) to perform SSRF attacks against internal services or cloud instance metadata endpoints.

Impact

Exploitation of this vulnerability allows for Server-Side Request Forgery attacks, where an attacker could access internal services on the same host or cloud instance metadata endpoints, potentially leading to unauthorized access or manipulation of sensitive data.

Remediation

Users can upgrade to Directus version 11.16.0 or later to address this vulnerability.

Added: Apr 6, 2026, 10:29 PM
Updated: Apr 6, 2026, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.4
exploitability
4.7
remediation
0.0
relevance
5.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.