CVE-2026-26008

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that leads to possible remote crash/memory corruption. This is because the CSMS sends UpdateAllowedEnergyTransferModes over the network. Version 2026.2.0 contains a patch.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:*

History

31 Mar 2026, 13:45

Type Values Removed Values Added
First Time Linuxfoundation
Linuxfoundation everest
CPE cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:*
References () https://github.com/EVerest/EVerest/security/advisories/GHSA-vw95-6jj7-3fv9 - () https://github.com/EVerest/EVerest/security/advisories/GHSA-vw95-6jj7-3fv9 - Vendor Advisory

30 Mar 2026, 13:26

Type Values Removed Values Added
Summary
  • (es) EVerest es una pila de software de carga de VE. Las versiones anteriores a la 2026.02.0 tienen un acceso fuera de límites (std::vector) que conduce a una posible caída remota/corrupción de memoria. Esto se debe a que el CSMS envía UpdateAllowedEnergyTransferModes a través de la red. La versión 2026.2.0 contiene un parche.

26 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 15:16

Updated : 2026-03-31 13:45


NVD link : CVE-2026-26008

Mitre link : CVE-2026-26008

CVE.ORG link : CVE-2026-26008


JSON object : View

Products Affected

linuxfoundation

  • everest
CWE
CWE-125

Out-of-bounds Read