Technology · npm
signalk-server (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in signalk-server (npm): 0 in the last 7 days and 1 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55591, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 2
- Exploited in the wild
- 0
About signalk-server (npm)
An implementation of a Signal K server for marine data exchange.
Latest signalk-server (npm) vulnerabilities
- CVE-2026-55591: Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in…mediumCVSS 5.8EPSS 0.3%
- CVE-2026-41893: SignalK Signal K Server brute-force protection bypass in WebSocket loginhighCVSS 7.5EPSS 0.5%
- CVE-2026-39320: Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription PathshighCVSS 7.5EPSS 0.7%
- CVE-2026-35038: SignalK signalk-server arbitrary prototype read in applicationDatamediumCVSS 6.5EPSS 0.4%
- CVE-2026-34083: Signal K Server OAuth code theft via unvalidated Host header in OIDCmediumCVSS 6.1EPSS 0.1%
- CVE-2026-33951: SignalK Signal K Server authentication bypass in sourcePriorities endpointhighCVSS 7.5EPSS 0.5%
- CVE-2026-33950: SignalK Signal K Server privilege escalation in /enableSecuritycriticalCVSS 9.4EPSS 0.5%
- CVE-2026-25228: SignalK Server path traversal in applicationData APIlowCVSS 3.1EPSS 0.4%
- CVE-2025-68620: Signal K Server JWT token theft via WebSocket enumerationlowCVSS 3.1EPSS 0.5%
- CVE-2025-69203: Signal K Server access request spoofing via X-Forwarded-For headerlowCVSS 3.1EPSS 0.3%
- CVE-2025-68619: Signal K Server remote code execution via malicious npm package installationlowCVSS 3.1EPSS 0.7%
- CVE-2025-68273: Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed EndpointsmediumCVSS 5.3EPSS 0.4%
- CVE-2025-68272: Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request FloodinghighCVSS 7.5EPSS 0.6%
- CVE-2025-66398: Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)criticalCVSS 9.6EPSS 20.1%
Most severe signalk-server (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-66398: Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)criticalCVSS 9.6EPSS 20.1%
- CVE-2026-33950: SignalK Signal K Server privilege escalation in /enableSecuritycriticalCVSS 9.4EPSS 0.5%
- CVE-2026-39320: Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription PathshighCVSS 7.5EPSS 0.7%
- CVE-2025-68272: Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request FloodinghighCVSS 7.5EPSS 0.6%
- CVE-2026-33951: SignalK Signal K Server authentication bypass in sourcePriorities endpointhighCVSS 7.5EPSS 0.5%
- CVE-2026-41893: SignalK Signal K Server brute-force protection bypass in WebSocket loginhighCVSS 7.5EPSS 0.5%
- CVE-2026-35038: SignalK signalk-server arbitrary prototype read in applicationDatamediumCVSS 6.5EPSS 0.4%
- CVE-2026-34083: Signal K Server OAuth code theft via unvalidated Host header in OIDCmediumCVSS 6.1EPSS 0.1%
- CVE-2026-55591: Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in…mediumCVSS 5.8EPSS 0.3%
- CVE-2025-68273: Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed EndpointsmediumCVSS 5.3EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/signalk-server.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "signalk-server (npm) vulnerabilities", https://junglewise.ai/threats/technologies/signalk-server, 26 September 2026.