CVE-2026-26073: EVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queue
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible std::queue/std::deque corruption. The trigger is powermeter public key update and EV session/error events (while OCPP not started). This results in a TSAN data race report and an ASAN/UBSAN misaligned address runtime error being observed. Version 2026.02.0 contains a patch.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26073?
CVE-2026-26073 is categorized as a high severity vulnerability due to heap corruption risks.
How do I fix CVE-2026-26073?
The recommended fix for CVE-2026-26073 is to upgrade to EVerest version 2026.02.0 or later.
Who is affected by CVE-2026-26073?
Users of EVerest versions prior to 2026.02.0 are at risk from CVE-2026-26073.
What causes CVE-2026-26073?
CVE-2026-26073 is caused by a data race during a power meter public key update and EV session/error events.
What software is impacted by CVE-2026-26073?
EVerest software versions earlier than 2026.02.0 are impacted by CVE-2026-26073.