[Announcement] Policy Update Regarding Response Headers for Image Access in OSS
Nov 21, 2025
Object Storage ServiceAffected Time
Details: To further enhance the security and compliance posture of Alibaba Cloud Object Storage Service (OSS), we are updating the default content-handling behavior for images. Effective 10:00:00 (UTC+8) on December 22, 2025, for buckets created after this date in select regions, the Content-Disposition:'attachment=filename;' header will be automatically added to the HTTP response for image files when they are accessed via a default domain. This change specifically applies to files with the following MIME types: image/jpeg, image/gif, image/tiff, image/png, image/webp, image/svg+xml, image/bmp, image/x-ms-bmp, image/x-cmu-raster, image/exr, image/x-icon, and image/heic. Consequently, when these files are accessed from a web browser, they will be downloaded as an attachment instead of being displayed directly. This upgrade will be rolled out to the following regions: China (Ulanqab), China (Heyuan), China (Guangzhou), China (Nanjing - Local Region). With the completion of this rollout, the policy will be uniformly enforced across all regions of the Alibaba Cloud public cloud.
If you use custom domain names that are mapped to the buckets to access the objects, the Content-Disposition:'attachment=filename;' header is not added to the response. For more information about how to use custom domain names to access OSS, see Access OSS using a custom domain name in the User Guide.
We have designed this upgrade process to minimize any impact on your services. Should you have any questions, require technical assistance or further clarification, contact us by submitting a ticket or calling the customer hotline. Thank you for your understanding and cooperation!