CVE-2026-61835 | Directus up to 11.x SSRF Protection is-denied-ip.ts 0.0.0.0 server-side request forgery
A vulnerability classified as problematic was found in Directus up to 11.x. This affects an unknown function of the file api/src/request/is-denied-ip.ts of the component SSRF Protection. Executing a manipulation of the argument 0.0.0.0 can lead to server-side request forgery.
This vulnerability appears as CVE-2026-61835. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More