Resource exhaustion in Directus - CVE-2025-30350
Published: March 26, 2025 / Updated: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the S3 asset handling component when processing a burst of HEAD requests. A remote attacker can send many HEAD requests to cause a denial of service.
The issue can make assets unavailable for all Directus access policies, including admin and public access.