---
id: CVE-2025-68272
title: Signal K Server is a server application that runs on a central hub in a boat
summary: >-
  Signal K Server is a server application that runs on a central hub in a boat.
  A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an
  unauthenticated attacker to crash the SignalK Server by flooding the access
  reque…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-770
vendor: signalk
product: signal_k_server
affected:
  - signal_k_server < 2.19.0
patched:
  - signal_k_server 2.19.0
published: '2026-01-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T08:10:00.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68272'
references:
  - url: 'https://github.com/SignalK/signalk-server/releases/tag/v2.19.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/SignalK/signalk-server/security/advisories/GHSA-7rqc-ff8m-7j23
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00564
epssPercentile: 0.44684
ingestedAt: '2026-10-01T08:40:11.723Z'
---

## Overview

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue.

## Affected

- `signal_k_server < 2.19.0`

## Remediation

Upgrade past the affected range:

- `signal_k_server 2.19.0`
