Executive brief
Directus is a headless CMS and content management platform that stores media assets in Amazon S3 cloud storage. A vulnerability in how it handles HEAD requests (used by syncing tools like Shopify to check file existence) causes socket connections to be left open without being consumed, exhausting the connection pool and making all assets unavailable to users with 403 errors.
Technical details
The vulnerability exists in Directus's S3 storage driver when handling HTTP HEAD requests. The root cause is improper stream handling in the AWS SDK integration: when a stream is requested from the S3 client but not consumed by the application code, it hangs indefinitely and holds a socket connection. After a burst of HEAD requests, all available sockets (controlled by STORAGE_CLOUD_MAX_SOCKETS) become exhausted, making new connections impossible and causing all subsequent asset requests to fail with 403 errors. This affects both the @directus/storage-driver-s3 package (>=9.22.0, fixed in 12.0.1) and the main directus package (>=9.22, fixed in 11.5.0). The issue is easily triggered and requires no authentication or user interaction, as HEAD requests are commonly issued by automated tools and CDNs.
Affected products
- Directus Directus >=9.22 <11.5.0
- Directus Storage Driver S3 >=9.22.0 <12.0.1
Timeline
- 2025-03-26: disclosed
- 2025-03-26: patched: Directus 11.5.0 and @directus/storage-driver-s3 12.0.1