CVE-2026-33009
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memory corruption). This is triggered by an MQTT everestexternal/nodered/{connector}/cmd/switchthreephaseswhile_charging message and results in Charger::shared_context / internal_context accessed concurrently without lock. Version 2026.02.0 contains a patch.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33009.json, https://github.com/EVerest/EVerest/security/advisories/GHSA-33qh-fg6f-jjx5, https://nvd.nist.gov/vuln/detail/CVE-2026-33009
