EVerest.everest-core is vulnerable to Integer Overflow
79
High Risk
SdpPacket::parse_header() adds the V2GTP header size to an attacker-controlled length field during ISO 15118-20 SDP session discovery without checking for overflow. When that length is near the maximum 32-bit value, the sum wraps, and a later subtraction for remaining bytes underflows to a huge size_t that is used as the next network read length. Depending on the transport, that read either loops indefinitely or writes past a stack buffer. The fix validates the packet length field before using it in remaining-byte calculations.
You are affected if you are using a version that falls within the vulnerable range and run everest-core with the ISO 15118-20 charging communication stack enabled and reachable on the local network.
EVerest.everest-core is vulnerable to Integer Overflow in versions 2024.9.2 - 2025.9.0.
Upgrade the EVerest.everest-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.