directus is vulnerable to Uncontrolled Resource Consumption
75
High Risk
A companion GraphQL system resolver file was not covered by an earlier alias-amplification deduplication fix, leaving several anonymously reachable, expensive resolvers un-deduplicated. Because GraphQL aliasing lets one document invoke the same field many times and the HTTP rate limiter counts requests rather than resolver invocations, a single anonymous request to the system GraphQL endpoint multiplies into many server-side operations. This lets an unauthenticated caller lock out accounts with guessable emails, flood arbitrary recipients with password-reset mail, and force many hashing operations to exhaust CPU. The fix deduplicates the affected system resolvers.
You are affected if you are using a version that falls within the vulnerable range.
directus is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 12.0.2.
Upgrade the directus library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant