Missing Release of Resource after Effective Lifetime in Directus - CVE-2025-30225
Published: March 26, 2025 / Updated: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource shutdown in asset transformation handling when processing malformed transformation requests. A remote attacker can send a burst of specially crafted transformation requests to cause a denial of service.
This issue affects S3-backed assets and can cause all assets to be served as HTTP 403 responses.