CVE-2025-68272

HIGH

Signal K Server < 2.19.0 - Unauthenticated Denial of Service via Access Request Endpoint Flooding

Title source: llm
STIX 2.1

Description

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0052
EPSS Percentile 39.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-770 CWE-400
Status published
Products (2)
npm/signalk-server 0 - 2.19.0npm
signalk/signal_k_server < 2.19.0
Published Jan 01, 2026
Tracked Since Feb 18, 2026