CVE-2025-30225: Directus's S3 assets become unavailable after a burst of malformed transformations
Summary When making many malformed transformation requests at once, at some point, all assets are being served as 403.
Details When I was investigating this issue, I have found that after a burst of malformed asset transformation requests, the amount of sockets held on Agent on NodeHttpHandler was always equal to STORAGECLOUDMAXSOCKETS making it impossible to have new connections causing assets to be inaccessible.
After looking into this issue on AWS SDK I found that if the stream is requested, it needs to be consumed otherwise will hang forever. And as can be seen here the stream is not consumed, because sharp will throw an error on the invalid arguments. For example ?height=xyz
The timeouts set here had no noticeable effect on tests made.
PoC This can be easily reproduced with the following steps: - setup AWS S3 storage - set STORAGECLOUDMAXSOCKETS: "50" (this value is lower than default for easier reproduction) - upload a file to your project - run this file (Replace the the file ID with the one you just uploaded): ts import axios from "axios";
async function start() { Array.from({ length: 400 }, (, i) => { axios .get( "http://localhost:8055/assets/e536aa35-3a81-4fa9-b856-3780584d38d8?width=100&height=XYZ" ) .then(() => console.log("✅")) .catch((e) => console.log("⛔", e.response?.status || e.code || e.message) ); }); }
start();
Here's an example:
https://github.com/user-attachments/assets/7f5a6f51-1c51-4d4d-aa4f-c4953e91714c
Impact This causes denial of assets for all policies of Directus, including Admin and Public.
Other sources
Directus is a real-time API and App dashboard for managing SQL database content. The @directus/storage-driver-s3 package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of malformed transformations. When making many malformed transformation requests at once, at some point, all assets are served as 403. This causes denial of assets for all policies of Directus, including Admin and Public. Version 12.0.1 of the @directus/storage-driver-s3 package, corresponding to version 11.5.0 of Directus, fixes the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/directusto a version that resolves this vulnerability.Fixed in 11.5.0 - Upgrade
Upgrade
npm/@directus/storage-driver-s3to a version that resolves this vulnerability.Fixed in 12.0.1 - Upgrade
Upgrade
@directus/storage-driver-s3to a version that resolves this vulnerability.Fixed in 12.0.1 - Upgrade
Upgrade
Directusto a version that resolves this vulnerability.Fixed in 11.5.0 - Configuration
Set STORAGE_CLOUD_MAX_SOCKETS to 50.
Directus (S3 storage driver) STORAGE_CLOUD_MAX_SOCKETS = 50 - Compensating control
Ensure the S3 asset transformation stream is consumed to prevent hanging connections after malformed transformation requests (the issue occurs because the stream is requested but not consumed, e.g., when sharp throws an error on invalid arguments such as ?height=xyz).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30225?
CVE-2025-30225 has a moderate severity level due to the potential for service disruption when handling malformed transformation requests.
How do I fix CVE-2025-30225?
To fix CVE-2025-30225, upgrade to directus version 11.5.0 or @directus/storage-driver-s3 version 12.0.1.
Which software is affected by CVE-2025-30225?
CVE-2025-30225 affects directus versions from 9.22.0 to 11.5.0 and @directus/storage-driver-s3 versions from 9.22.0 to 12.0.1.
What is the impact of CVE-2025-30225 on system performance?
CVE-2025-30225 may cause a denial of service, leading to assets being served with a 403 error after a burst of malformed requests.
Can CVE-2025-30225 be exploited remotely?
Yes, CVE-2025-30225 can potentially be exploited remotely by overwhelming the system with malformed transformation requests.