{"id":"GHSA-jr94-gj3h-c8rf","summary":"Directus Vulnerable to User Enumeration via Password Reset Timing Attack","details":"### Summary\n\nA timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url parameter is provided, the response time differs by approximately 500ms between existing and non-existing users, enabling reliable user enumeration.\n\n### Details\n\nThe password reset endpoint implements a timing protection mechanism to prevent user enumeration; however, URL validation executes before the timing protection is applied. This allows an attacker to distinguish between valid and invalid user accounts based on response timing differences.\n\n### Impact\n\nThis vulnerability violates user privacy and may facilitate targeted phishing attacks by allowing attackers to confirm the existence of user accounts.","aliases":["CVE-2026-26185"],"modified":"2026-02-13T17:48:48.075974Z","published":"2026-02-12T22:13:04Z","database_specific":{"nvd_published_at":"2026-02-12T22:16:07Z","cwe_ids":["CWE-203"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-12T22:13:04Z"},"references":[{"type":"WEB","url":"https://github.com/directus/directus/security/advisories/GHSA-jr94-gj3h-c8rf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26185"},{"type":"WEB","url":"https://github.com/directus/directus/pull/26485"},{"type":"WEB","url":"https://github.com/directus/directus/commit/e69aa7a5248c6e3e822cb1ac354dee295df90b2a"},{"type":"PACKAGE","url":"https://github.com/directus/directus"},{"type":"WEB","url":"https://github.com/directus/directus/releases/tag/v11.14.1"}],"affected":[{"package":{"name":"directus","ecosystem":"npm","purl":"pkg:npm/directus"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.14.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-jr94-gj3h-c8rf/GHSA-jr94-gj3h-c8rf.json"}},{"package":{"name":"@directus/api","ecosystem":"npm","purl":"pkg:npm/%40directus/api"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"32.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-jr94-gj3h-c8rf/GHSA-jr94-gj3h-c8rf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}