Signalk
Signalk Signal K Server: vulnerabilidades y CVE
Signalk Signal K Server tiene 15 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses15
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55591 | Media (5.8) | 0.30% | — | 15 sept 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters… |
| CVE-2026-41893 | Alta (8.7) | 0.51% | — | 9 may 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default:… |
| CVE-2026-39320 | Alta (7.5) | 0.66% | — | 21 abr 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (ReDoS) attack within the WebSocket… |
| CVE-2026-35038 | Baja (2.1) | 0.41% | — | 2 abr 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a… |
| CVE-2026-34083 | Media (6.1) | 0.14% | — | 2 abr 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerability in its OIDC login and logout handlers where the unvalidated HTTP… |
| CVE-2026-33951 | Media (6.9) | 0.54% | — | 2 abr 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the SignalK Server exposes an unauthenticated HTTP endpoint that allows remote attackers to modify navigation… |
| CVE-2026-33950 | Crítica (9.4) | 0.48% | — | 2 abr 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated… |
| CVE-2026-25228 | Media (4.3) | 0.43% | — | 2 feb 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to… |
| CVE-2026-23515 | Alta (8.8) | 4.6% | — | 2 feb 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on… |
| CVE-2025-69203 | Alta (8.8) | 0.30% | — | 1 ene 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by themselves and with an information… |
| CVE-2025-68620 | Crítica (9.1) | 0.54% | — | 1 ene 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior… |
| CVE-2025-68619 | Alta (7.3) | 0.71% | — | 1 ene 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the… |
| CVE-2025-68273 | Media (5.3) | 0.82% | — | 1 ene 2026 | Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information,… |
| CVE-2025-68272 | Alta (7.5) | 0.56% | — | 1 ene 2026 | Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by… |
| CVE-2025-66398 | Alta (8.8) | 20% | — | 1 ene 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.