Junglewise Threat Intelligence

CVE-2026-35441: Directus resource exhaustion via GraphQL alias amplification

CVE-2026-35441 · Severity: medium · CVSS 6.5 · Published 2026-04-06

Technologies: directus (npm). Vendors: npm, Directus.

Executive brief

Directus is an open-source data platform used to manage SQL database content through an API and dashboard. A vulnerability in its GraphQL interface allows an authenticated user to overwhelm the system by sending a single request that triggers many complex database operations simultaneously. This can lead to significant performance slowdowns or a complete service outage, preventing legitimate users from accessing the platform.

Technical details

Directus GraphQL endpoints (/graphql and /graphql/system) fail to deduplicate resolver invocations within a single request. An authenticated attacker can use GraphQL aliasing to repeat expensive relational queries multiple times in one request, bypassing existing token and depth limits which are applied per alias rather than per request. Because rate limiting is disabled by default, this results in linear multiplication of database load, leading to CPU, memory, and I/O exhaustion. The vulnerability is rooted in CWE-400 and CWE-770 and is resolved in version 11.17.0 by implementing a request-scoped resolver deduplication mechanism.

Affected products

  • Directus Directus < 11.17.0

Timeline

  • 2026-04-02: advisory: Vendor advisory published on GitHub
  • 2026-04-06: disclosed: CVE published

References

Related threats