Race Condition Affecting EVerest/everest-core package, versions [,2026.02.0-rc3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-EVERESTEVERESTCORE-15809100
  • published29 Mar 2026
  • disclosed26 Mar 2026
  • creditFinder16

Introduced: 26 Mar 2026

CVE-2026-33009  (opens in a new tab)
CWE-362  (opens in a new tab)

How to fix?

Upgrade EVerest/everest-core to version 2026.02.0-rc3 or higher.

Overview

Affected versions of this package are vulnerable to Race Condition in the handling of MQTT everest_external/nodered/{connector}/cmd/switch_three_phases_while_charging messages, where Charger::shared_context and internal_context are accessed concurrently without proper locking. An attacker can cause charger state corruption or denial of service by sending crafted MQTT messages that trigger concurrent access.

CVSS Base Scores

version 4.0
version 3.1