EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/`std::deque` corruption. The trigger is powermeter public key update and EV session/error events (while OCPP not started). This results in a TSAN data race report and an ASAN/UBSAN misaligned address runtime error being observed. Version 2026.02.0 contains a patch.
References
| Link | Resource |
|---|---|
| https://github.com/EVerest/EVerest/security/advisories/GHSA-jf36-f4f9-7qc2 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-26 17:16
Updated : 2026-06-17 10:25
NVD link : CVE-2026-26073
Mitre link : CVE-2026-26073
CVE.ORG link : CVE-2026-26073
JSON object : View
Products Affected
linuxfoundation
- everest
