OsVault/npm/signalk-server
npm1 critical

signalk-server

12 known vulnerabilities · 1 critical · 0 high

CVE-2025-68272

Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Published Jan 2, 2026
CVE-2025-68273

Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints

Published Jan 2, 2026
CVE-2026-25228

SignalK Server has Path Traversal leading to information disclosure

Published Feb 2, 2026
CVE-2025-68619

Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package

Published Jan 2, 2026
CVE-2025-68620

Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling

Published Jan 2, 2026
GHSA-7gcj-phff-2884

Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths

Published Apr 21, 2026
CVE-2026-34083MEDIUM
Risk: 30.5/100

Signal K Server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow

Published Apr 3, 2026
CVE-2026-33951
Risk: 0.09/100

Signal K Server: Unauthenticated Source Priorities Manipulation

Published Apr 3, 2026
CVE-2026-35038
Risk: 0.03/100

Signal K Server: Arbitrary Prototype Read via `from` Field Bypass

Published Apr 3, 2026
CVE-2025-66398

Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)

Published Jan 2, 2026
CVE-2026-33950CRITICAL
Risk: 47.01/100

Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurity

Published Apr 3, 2026
CVE-2025-69203

Signal K Server Vulnerable to Access Request Spoofing

Published Jan 2, 2026
Check your entire dependency tree at onceRun dependency scan →