directus is vulnerable to Uncontrolled Resource Consumption
75
High Risk
Directus exposes the utility endpoints for hash generation and verification to unauthenticated callers, and the verify path validates a caller-supplied Argon2 hash directly. Because Argon2 reads its memory, iteration, and parallelism cost parameters from the encoded hash string, a single request can force the server into a very expensive verification. A low volume of unauthenticated requests can exhaust CPU and memory on the shared authentication compute path, degrading or denying login and other flows. The fix removes the hash generate and verify endpoints along with their GraphQL and SDK equivalents.
You are affected if you are using a version that falls within the vulnerable range.
directus is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 12.0.2.
Upgrade the directus library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant