CVE-2025-68272

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:*

History

06 Jan 2026, 18:23

Type Values Removed Values Added
CPE cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:*
First Time Signalk
Signalk signal K Server
References () https://github.com/SignalK/signalk-server/releases/tag/v2.19.0 - () https://github.com/SignalK/signalk-server/releases/tag/v2.19.0 - Release Notes
References () https://github.com/SignalK/signalk-server/security/advisories/GHSA-7rqc-ff8m-7j23 - () https://github.com/SignalK/signalk-server/security/advisories/GHSA-7rqc-ff8m-7j23 - Exploit, Vendor Advisory

01 Jan 2026, 19:15

Type Values Removed Values Added
References
  • () https://github.com/SignalK/signalk-server/releases/tag/v2.19.0 -

01 Jan 2026, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-01 18:15

Updated : 2026-01-06 18:23


NVD link : CVE-2025-68272

Mitre link : CVE-2025-68272

CVE.ORG link : CVE-2025-68272


JSON object : View

Products Affected

signalk

  • signal_k_server
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling