CVE-2026-26071: Linuxfoundation Everest

Medium severity, CVSS 4.2. EPSS: 0.1% chance of exploitation in the next 30 days.

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurrent access. with heap-use-after-free possible. This is triggered by EVCCID update (EV/ISO15118) and OCPP session/authorization events. Version 2026.02.0 contains a patch.

Affected products

Published 2026-03-26. Last modified 2026-06-17.