CVE-2025-30350: Directus's S3 assets become unavailable after a burst of HEAD requests
(updated )
There’s some tools that use Directus to sync content and assets. Some of those tools use HEAD method, like Shopify, to check the existence of files. Although, when making many HEAD requests at once, at some point, all assets are being served as 403.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-30350 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →