216.73.216.226

CVE-2025-68272

· Published 01/01/2026 18:15 · Modified 01/01/2026 19:15

Labels: CVE-2025-68272 2026-01-01CVE-2025-68272CWE-400[email protected]

Essential information

Published
01/01/2026 18:15
Modified
01/01/2026 19:15
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
signal k / signal k server cpe:2.3:a:signal_k:signal_k_server:<2.19.0:*:*:*:*:*:*:*

References