Junglewise Threat Intelligence

CVE-2025-67419: EverShop denial of service in image processing API

CVE-2025-67419 · Severity: low · CVSS 3.1 · Published 2026-01-05

Technologies: @evershop/evershop (npm), EverShop. Vendors: npm, EverShop.

Executive brief

EverShop is an open-source e-commerce platform used to build online stores. A vulnerability in the image processing endpoint allows attackers to trigger uncontrolled resource consumption by uploading specially crafted SVG files, causing the application server to become unavailable to legitimate customers.

Technical details

A Denial of Service vulnerability in the GET /images API endpoint fails to enforce limits on SVG element shadow tree height or pattern tile dimensions during file processing. The vulnerability is reachable without authentication, allowing an unauthenticated attacker to submit maliciously crafted SVG files that trigger unbounded memory or CPU consumption. This results in exhaustion of application server resources and denial of service. The vulnerability affects EverShop versions 2.1.0 and earlier with no identified upstream patch yet available.

Affected products

  • EverShop EverShop 2.1.0 and prior

Timeline

  • 2026-01-05: disclosed: GHSA advisory published
  • 2026-01-05: other: CVE-2025-67419 assigned

References

Related threats