CVE-2026-26074
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible std::mapstd::queue corruption. The trigger is CSMS GetLog/UpdateFirmware request (network) with an EVSE fault event (physical). This results in TSAN reports concurrent access (data race) to event_queue. Version 2026.2.0 contains a patch.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26074.json, https://github.com/EVerest/EVerest/security/advisories/GHSA-p3hg-vqgv-h524, https://nvd.nist.gov/vuln/detail/CVE-2026-26074
