Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

signalk-server — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in signalk-server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for signalk-server, a navigation and marine electronics server software. It compiles data related to common weakness enumerations and security flaws affecting this specific open-source product. The collection covers publicly disclosed security issues, including those identified through independent research and vendor patches, spanning from the initial release of the software to the present day. This range ensures a comprehensive view of the product's evolving security posture and historical exposure to known risks. Users can utilize this resource to track vendor advisories and patch cycles, gaining insight into how the maintainers address critical flaws. Additionally, the page aids in understanding specific weakness classes by showing how they manifest within the signalk-server architecture, providing context for developers and system administrators. Readers can also look up the product's vulnerability history to assess long-term stability and security hygiene. This aggregated view supports informed decision-making regarding upgrades, mitigation strategies, and risk management. By centralizing this information, the page simplifies the process of monitoring security updates and evaluating the trustworthiness of the software stack in marine environments. The content is structured to facilitate quick reference and detailed analysis, supporting both automated scanning tools and manual security reviews. All listed items are sourced from reliable vulnerability databases and official release notes to ensure accuracy. This approach helps stakeholders maintain compliance and protect against potential exploits targeting known weaknesses in the system.

Vendor: SignalK

CVE IDTitleCVSSSeverityPublished
CVE-2026-41893 Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force) CWE-307 9.1 -2026-05-09
CVE-2026-39320 Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths CWE-400 7.5 High2026-04-21
CVE-2026-35038 signalk-server: Arbitrary Prototype Read via `from` Field Bypass CWE-20 6.5AIMediumAI2026-04-02
CVE-2026-34083 signalk-server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow CWE-346 6.1 Medium2026-04-02
CVE-2026-33951 signalk-server: Unauthenticated Source Priorities Manipulation CWE-284 7.5AIHighAI2026-04-02
CVE-2026-33950 signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity CWE-285 9.4 Critical2026-04-02
CVE-2026-25228 SignalK Server has Path Traversal leading to information disclosure CWE-22 5.0 Medium2026-02-02
CVE-2026-23515 RCE - Command Injection in Signal K set-system-time plugin CWE-78 10.0 Critical2026-02-02
CVE-2025-69203 Signal K Server Vulnerable to Access Request Spoofing CWE-290 6.3 Medium2026-01-01
CVE-2025-68619 Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package CWE-94 9.1 -2026-01-01
CVE-2025-68620 Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling CWE-288 9.1 Critical2026-01-01
CVE-2025-68273 Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints CWE-200 5.3 Medium2026-01-01
CVE-2025-68272 Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding CWE-400 7.5 High2026-01-01
CVE-2025-66398 Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE) CWE-78 9.7 Critical2026-01-01

All 14 known CVE vulnerabilities affecting signalk-server with full Chinese analysis, references, and POCs where available.