The open-source EV charging software stack EVerest patched two high-severity vulnerabilities in version 2026.02.0, including a stack-based buffer overflow tracked as CVE-2026-23995 and a remotely triggerable data race tracked as CVE-2026-33009. The buffer overflow affects CAN interface initialization in versions prior to 2026.02.0 when an interface name longer than IFNAMSIZ is passed to CAN open routines, overflowing ifreq.ifr_name and potentially corrupting adjacent stack memory before privilege checks occur. The issue was classified as CWE-121 and could lead to code execution, with related advisory GHSA-p47c-2jpr-mpwx.
The second flaw, CVE-2026-33009, allows remote triggering through the MQTT topic everest_external/nodered/{connector}/cmd/switch_three_phases_while_charging, where concurrent access to charger state objects can cause undefined C++ behavior, state corruption, and possible memory corruption. The vulnerability was classified as CWE-362 and carries high availability impact because it can disrupt charger operation without authentication. Both issues affect EVerest releases before 2026.02.0, and organizations running EV charging infrastructure on the platform should prioritize upgrading to the patched release and review the corresponding advisory GHSA-33qh-fg6f-jjx5.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Two new vulnerabilities in EVerest were publicly recorded: CVE-2026-23995, a stack buffer overflow in ifreq.ifr_name during CAN interface initialization, and CVE-2026-33009, a data race in MQTT switch-phases handling that can corrupt charger state. GitHub security advisories GHSA-p47c-2jpr-mpwx and GHSA-33qh-fg6f-jjx5 were referenced alongside the disclosures.
EVerest version 2026.02.0 was released with fixes for two flaws affecting earlier versions: a stack-based buffer overflow in CAN interface initialization and a remotely triggerable MQTT switch-phases data race. The patched issues were later tracked as CVE-2026-23995 and CVE-2026-33009.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.