CVE-2026-27828 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 handle_session_setup use after free (GHSA-5g3v-qc79-qqwr / EUVD-2026-16228)
A vulnerability categorized as critical has been discovered in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0. The impacted element is the function ISO15118_chargerImpl::handle_session_setup. Such manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-27828. The attack can only be performed from a local environment. No exploit is available.
It is advisable to upgrade the affected component.