Vulnerabilities/

evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API

Severity:
High

Description

A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server’s resources via the “GET /images” API.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@evershop/evershop
Anything's wrong? Let us know Last updated on January 05, 2026