EVerest is an EV charging software stack. Prior to version 2026.02.0, HomeplugMessage::setup_payload trusts len after an assert; in release builds the check is removed, so oversized SLAC payloads are memcpy'd into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from network-provided frames. Version 2026.02.0 contains a patch.
{
"cwe_ids": [
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22790.json",
"cna_assigner": "GitHub_M"
}