VendorsLinux Foundationeverestany version
Vulnerabilities

Linux Foundation Everest any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2026-27815
EVerest: ISO15118 session_setup payment options overflow can corrupt EVSE state
Published 2026-03-26 · Analyzed
9.1EPSS 0.003
CVE-2026-27816
EVerest's ISO15118 update_energy_transfer_modes overflow can corrupt EVSE state
Published 2026-03-26 · Analyzed
9.1EPSS 0.002
CVE-2026-22790
EVerest's unchecked SLAC payload length causes stack overflow in HomeplugMessage::setup_payload
Published 2026-03-26 · Analyzed
8.8EPSS 0.005
CVE-2026-23995
EVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZ
Published 2026-03-26 · Analyzed
8.4EPSS 0.002
CVE-2026-22593
EVerest has off-by-one stack buffer overflow in IsoMux certificate filename parsing
Published 2026-03-26 · Analyzed
8.4EPSS 0.001
CVE-2025-68137
EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loop
Published 2026-01-21 · Analyzed
8.31 PoCEPSS 0.011
CVE-2026-33009
EVerest: MQTT Switch-Phases Command Data Race Causing Charger State Corruptio
Published 2026-03-26 · Analyzed
8.2EPSS 0.002
CVE-2026-26008
EVerest has OOB via EVSE ID Indexing Mismatch in OCPP 2.0.1 UpdateAllowedEnergyTransferModes
Published 2026-03-26 · Analyzed
7.5EPSS 0.004
CVE-2026-27828
EVerest: ISO15118 session_setup use-after-free can crash EVSE process
Published 2026-03-26 · Analyzed
7.5EPSS 0.003
CVE-2025-68133
EVerest's unlimited connections can lead to DoS through operating system resource exhaustion
Published 2026-01-21 · Analyzed
7.4EPSS 0.004
CVE-2025-68136
EVerest's inadequate session handling can lead to memory-related errors or exhaustion of the operating system’s file descriptors, resulting in a denial of service
Published 2026-01-21 · Analyzed
7.4EPSS 0.003
CVE-2025-68141
EVerest vulnerable to null pointer dereference during DC_ChargeLoopRes document deserialization
Published 2026-01-21 · Analyzed
7.4EPSS 0.003
CVE-2025-68134
EVerest's use of assert functions can potentially lead to denial of service
Published 2026-01-21 · Analyzed
7.4EPSS 0.002
CVE-2026-26074
EVerest: OCPP201 startup event_queue lock mismatch leads to std::map/std::queue data race
Published 2026-03-26 · Analyzed
7.0EPSS 0.001
CVE-2025-68135
EVerest's inadequate exception handling leads to denial of service
Published 2026-01-21 · Analyzed
6.5EPSS 0.003
CVE-2026-29044
EVerest: Charging Continues When WithdrawAuthorization Is Processed Before TransactionStarted
Published 2026-03-26 · Analyzed
6.5EPSS 0.003
CVE-2026-26073
EVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queue
Published 2026-03-26 · Analyzed
5.9EPSS 0.003
CVE-2026-24003
EvseV2G has sequence state validation bypass
Published 2026-01-26 · Analyzed
5.3EPSS 0.003
CVE-2026-27813
EVerest has use-after-free in auth timeout timer via race condition
Published 2026-03-26 · Analyzed
5.3EPSS 0.001
CVE-2026-33015
EVerest has RemoteStop Bypass via BCB Toggle Session Restart
Published 2026-03-26 · Analyzed
5.2EPSS 0.002
CVE-2026-33014
EVerest has Delayed Authorization Response Bypasses Termination After RemoteStop
Published 2026-03-26 · Analyzed
5.2EPSS 0.002
CVE-2025-68132
EVerest has out-of-bounds read in DZG_GSH01 SLIP CRC parser that can crash powermeter driver
Published 2026-01-21 · Analyzed
4.6EPSS 0.003
CVE-2026-26070
EVerest: OCPP 2.0.1 EV SoC Update Race Causes Charge Point Crash
Published 2026-03-26 · Analyzed
4.6EPSS 0.001
CVE-2025-68139
In EVerest, by default, the EV is responsible for closing the connection if the module encounters an error during request processing
Published 2026-01-21 · Analyzed
4.3EPSS 0.002
CVE-2025-68140
EVerest allows null session ID to bypass session ID verification
Published 2026-01-21 · Analyzed
4.3EPSS 0.002
CVE-2026-23955
EVerest vulnerable to concatenation of strings literal and integers
Published 2026-01-21 · Analyzed
4.2EPSS 0.002
CVE-2026-26072
EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_map
Published 2026-03-26 · Analyzed
4.2EPSS 0.001
CVE-2026-27814
EVerest EvseManager phase-switch path has unsynchronized shared-state access race condition
Published 2026-03-26 · Analyzed
4.2EPSS 0.001
CVE-2026-26071
EVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑Free
Published 2026-03-26 · Analyzed
4.2EPSS 0.001