CVE-2025-30350: Directus's S3 assets become unavailable after a burst of HEAD requests
Summary There's some tools that use Directus to sync content and assets. Some of those tools use HEAD method, like Shopify, to check the existence of files. Although, when making many HEAD requests at once, at some point, all assets are being served as 403.
Details When I was investigating this issue, I have found that after the burst of HEAD requests, the amount of sockets held on Agent on NodeHttpHandler was always equal to STORAGECLOUDMAXSOCKETS making it impossible to have new connections causing assets to be inaccessible.
After looking into this issue on AWS SDK I found that if the stream is requested, it needs to be consumed otherwise will hang forever. And as can be seen here the stream is not consumed.
The timeouts set here had no noticeable effect on tests made.
PoC This can be easily reproduced with the following steps: - setup AWS S3 storage - set STORAGECLOUDMAXSOCKETS: "50" (this value is lower than default for easier reproduction) - upload a file to your project - run this file (Replace the the file ID with the one you just uploaded): ts import axios from "axios";
async function start() { Array.from({ length: 400 }, (, i) => { axios .head( "http://localhost:8055/assets/e536aa35-3a81-4fa9-b856-3780584d38d8" ) .then(() => console.log("✅")) .catch((e) => console.log("⛔", e.response?.status || e.code || e.message) ); }); }
start();
Here's an example:
https://github.com/user-attachments/assets/29d65bf0-5637-478f-a215-083c2ded3753
Impact This causes denial of assets for all policies of Directus, including Admin and Public.
Other sources
Directus is a real-time API and App dashboard for managing SQL database content. The @directus/storage-driver-s3 package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of HEAD requests. Some tools use Directus to sync content and assets, and some of those tools use the HEAD method to check the existence of files. When making many HEAD requests at once, at some point, all assets are eventually served as 403. This causes denial of assets for all policies of Directus, including Admin and Public. Version 12.0.1 of the @directus/storage-driver-s3 package, corresponding to version 11.5.0 of Directus, fixes the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/directusto a version that resolves this vulnerability.Fixed in 11.5.0 - Upgrade
Upgrade
npm/@directus/storage-driver-s3to a version that resolves this vulnerability.Fixed in 12.0.1 - Upgrade
Upgrade
@directus/storage-driver-s3to a version that resolves this vulnerability.Fixed in 12.0.1 - Upgrade
Upgrade
Directusto a version that resolves this vulnerability.Fixed in 11.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30350?
The severity of CVE-2025-30350 can lead to intermittent 403 errors when multiple HEAD requests are made, affecting the availability of assets.
How do I fix CVE-2025-30350?
To fix CVE-2025-30350, upgrade to Directus version 11.5.0 or @directus/storage-driver-s3 version 12.0.1.
What causes the 403 errors in CVE-2025-30350?
The 403 errors in CVE-2025-30350 occur when making a large number of HEAD requests simultaneously which causes the server to block access.
Which Directus versions are affected by CVE-2025-30350?
Directus versions between 9.22 and 11.5.0 are affected by CVE-2025-30350.
Is CVE-2025-30350 specific to any storage driver?
Yes, CVE-2025-30350 specifically affects the @directus/storage-driver-s3 version from 9.22.0 to 12.0.1.