{"id":"CVE-2024-39895","aliases":["GHSA-7hmh-pfrp-vcx4"],"url":"https://o3.security/vulnerability/CVE-2024-39895","summary":"Directus GraphQL Field Duplication Denial of Service (DoS)","details":"Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by field duplication in GraphQL is a type of attack where an attacker exploits the flexibility of GraphQL to overwhelm a server by requesting the same field multiple times in a single query. This can cause the server to perform redundant computations and consume excessive resources, leading to a denial of service for legitimate users. Request to the endpoint /graphql are sent when visualizing graphs generated at a dashboard. By modifying the data sent and duplicating many times the fields a DoS attack is possible. This vulnerability is fixed in 10.12.0.","published":"2024-07-08T16:47:44.673Z","modified":"2026-08-12T03:51:15.302278786Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00795,"percentile":0.54633,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"@directus/env","fixedVersion":"1.1.6"}],"fix":{"url":"https://github.com/directus/directus/commit/543b345695071c1de61a35004bd063fe59dba0c8","label":"directus/directus@543b345"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39895.json"},{"type":"ADVISORY","url":"https://github.com/directus/directus/security/advisories/GHSA-7hmh-pfrp-vcx4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39895"},{"type":"FIX","url":"https://github.com/directus/directus/commit/543b345695071c1de61a35004bd063fe59dba0c8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.302278786Z"}}