CVE-2026-33009
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memo
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memory corruption). This is triggered by an MQTT everest_external/nodered/{connector}/cmd/switch_three_phases_while_charging message and results in Charger::shared_context / internal_context accessed concurrently without lock.
Version 2026.02.0 contains a patch.
HIGH · CVSS 8.2
EPSS 0.0002
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0