Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7rqc-ff8m-7j23 | Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding |
Tue, 06 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Signalk signal K Server
|
|
| CPEs | cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Signalk signal K Server
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Signalk
Signalk signalk-server |
|
| Vendors & Products |
Signalk
Signalk signalk-server |
Fri, 02 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Jan 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 01 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue. | |
| Title | Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding | |
| Weaknesses | CWE-400 CWE-770 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-02T18:55:16.709Z
Reserved: 2025-12-16T14:05:31.364Z
Link: CVE-2025-68272
Updated: 2026-01-02T18:55:12.476Z
Status : Analyzed
Published: 2026-01-01T18:15:40.700
Modified: 2026-01-06T18:23:55.360
Link: CVE-2025-68272
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:14:45Z
Github GHSA