Home

Description

A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles during the processing of SVG files, resulting in unbounded resource consumption and system-wide denial of service.

PUBLISHED Reserved 2025-12-08 | Published 2026-01-05 | Updated 2026-01-05 | Assigner mitre

References

github.com/evershopcommerce/evershop

github.com/dos-m0nk3y/CVE/tree/main/CVE-2025-67419

cve.org (CVE-2025-67419)

nvd.nist.gov (CVE-2025-67419)

Download JSON