CVE-2025-68272High· 7.5▾ TwilightSignal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access reque…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (/signalk/v1/access/requests). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue.
signal_k_server < 2.19.0Upgrade past the affected range:
signal_k_server 2.19.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-68620Critical· 9.1Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-69203Medium· 6.3Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-68273Medium· 5.3Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-68619High· 7.2Signal K Server is a server application that runs on a central hub in a boat
CVE-2025-66398Critical· 9.6Signal K Server is a server application that runs on a central hub in a boat
CVE-2024-12254High· 7.5Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark"