CVE-2025-30350: Directus's S3 assets become unavailable after a burst of HEAD requests

Published Mar 26, 2025
·
Updated

Summary There's some tools that use Directus to sync content and assets. Some of those tools use HEAD method, like Shopify, to check the existence of files. Although, when making many HEAD requests at once, at some point, all assets are being served as 403.

Details When I was investigating this issue, I have found that after the burst of HEAD requests, the amount of sockets held on Agent on NodeHttpHandler was always equal to STORAGECLOUDMAXSOCKETS making it impossible to have new connections causing assets to be inaccessible.

After looking into this issue on AWS SDK I found that if the stream is requested, it needs to be consumed otherwise will hang forever. And as can be seen here the stream is not consumed.

The timeouts set here had no noticeable effect on tests made.

PoC This can be easily reproduced with the following steps: - setup AWS S3 storage - set STORAGECLOUDMAXSOCKETS: "50" (this value is lower than default for easier reproduction) - upload a file to your project - run this file (Replace the the file ID with the one you just uploaded): ts import axios from "axios";

async function start() { Array.from({ length: 400 }, (, i) => { axios .head( "http://localhost:8055/assets/e536aa35-3a81-4fa9-b856-3780584d38d8" ) .then(() => console.log("✅")) .catch((e) => console.log("⛔", e.response?.status || e.code || e.message) ); }); }

start();

Here's an example:

https://github.com/user-attachments/assets/29d65bf0-5637-478f-a215-083c2ded3753

Impact This causes denial of assets for all policies of Directus, including Admin and Public.

Other sources

Directus is a real-time API and App dashboard for managing SQL database content. The @directus/storage-driver-s3 package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of HEAD requests. Some tools use Directus to sync content and assets, and some of those tools use the HEAD method to check the existence of files. When making many HEAD requests at once, at some point, all assets are eventually served as 403. This causes denial of assets for all policies of Directus, including Admin and Public. Version 12.0.1 of the @directus/storage-driver-s3 package, corresponding to version 11.5.0 of Directus, fixes the issue.

MITRE

Affected Software

3 affected componentsFixes available
npm/directus>=9.22<11.5.0
11.5.0
npm/@directus/storage-driver-s3>=9.22.0<12.0.1
12.0.1
Monospace Directus Node.js>=9.22.0<11.5.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/directus to a version that resolves this vulnerability.

    Fixed in 11.5.0
  2. Upgrade

    Upgrade npm/@directus/storage-driver-s3 to a version that resolves this vulnerability.

    Fixed in 12.0.1
  3. Upgrade

    Upgrade @directus/storage-driver-s3 to a version that resolves this vulnerability.

    Fixed in 12.0.1
  4. Upgrade

    Upgrade Directus to a version that resolves this vulnerability.

    Fixed in 11.5.0

Event History

Mar 26, 2025
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
Affected Software
Advisory Published
via GitHub·05:20 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-30350?

The severity of CVE-2025-30350 can lead to intermittent 403 errors when multiple HEAD requests are made, affecting the availability of assets.

2

How do I fix CVE-2025-30350?

To fix CVE-2025-30350, upgrade to Directus version 11.5.0 or @directus/storage-driver-s3 version 12.0.1.

3

What causes the 403 errors in CVE-2025-30350?

The 403 errors in CVE-2025-30350 occur when making a large number of HEAD requests simultaneously which causes the server to block access.

4

Which Directus versions are affected by CVE-2025-30350?

Directus versions between 9.22 and 11.5.0 are affected by CVE-2025-30350.

5

Is CVE-2025-30350 specific to any storage driver?

Yes, CVE-2025-30350 specifically affects the @directus/storage-driver-s3 version from 9.22.0 to 12.0.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203