CVE-2025-67419: High severity evershop vulnerability
Published Jan 5, 2026
·Updated
A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles during the processing of SVG files, resulting in unbounded resource consumption and system-wide denial of service.
Affected Software
3 affected components
evershop<2.1.0
npm/@evershop/evershop<=2.1.0
evershop Evershop Node.js<=2.1.0
Event History
Jan 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Data Sourced
via GitHub·09:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67419?
CVE-2025-67419 is classified as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2025-67419?
To fix CVE-2025-67419, upgrade evershop to version 2.1.1 or later.
3
Who is affected by CVE-2025-67419?
CVE-2025-67419 affects evershop versions 2.1.0 and prior.
4
Can CVE-2025-67419 be exploited remotely?
Yes, CVE-2025-67419 can be exploited by unauthenticated attackers remotely.
5
What component is vulnerable in CVE-2025-67419?
CVE-2025-67419 specifically affects the 'GET /images' API in evershop.