These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-41893 affects Signal K Server versions before 2.25.0. The HTTP login endpoints are rate-limited, but the WebSocket login path accepts username/password messages without the same protection, allowing repeated guessing at the pace of bcrypt verification. The issue was addressed in version 2.25.0.
CVE-2026-35038 is an arbitrary prototype read vulnerability in Signal K Server before version 2.24.0. A low-privileged authenticated user can bypass prototype boundary filtering to extract internal functions and properties from the global prototype object, violating data isolation. This issue allows attackers to access more information than they should, potentially leading to further exploitation. Users o [truncated]
CVE-2025-69203 debrief based on the supplied source corpus. The CVE record was published on 2026-01-01T19:15:54.067Z and has not been modified since then. The vulnerability affects Signal K Server instances, particularly those with access to the admin UI, and allows attackers to request elevated permissions while appearing to request readonly access, and spoof their IP address to appear to originate from [truncated]
CVE-2025-68620 debrief based on the supplied source corpus. Signal K Server versions prior to 2.19.0 have a critical vulnerability that allows for authentication bypass through a combination of unauthenticated WebSocket request enumeration and token polling. The vulnerability enables attackers to steal JWT authentication tokens and hijack legitimate device credentials with zero authentication. The attack [truncated]
CVE-2025-68619 debrief based on the supplied source corpus. The CVE record was published on 2026-01-01T19:15:53.777Z and has not been modified since then. The vulnerability exists in Signal K Server versions prior to 2.19.0, where an administrator can install npm packages through a REST API endpoint, allowing for arbitrary code execution via malicious postinstall scripts. This issue enables attackers with [truncated]
CVE-2025-68273 is a medium-severity vulnerability in Signal K Server versions prior to 2.19.0 that allows unauthenticated information disclosure. This exposure facilitates reconnaissance for further attacks by allowing retrieval of sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. Defenders responsible for Signal K Server installa [truncated]
A Denial of Service (DoS) vulnerability in Signal K Server versions prior to 2.19.0 allows an unauthenticated attacker to crash the server by flooding the access request endpoint, causing a 'JavaScript heap out of memory' error due to unbounded in-memory storage of request objects. This issue affects Signal K Server installations in marine environments, potentially disrupting operations. Defenders should [truncated]
CVE-2025-66398 is a critical vulnerability in Signal K Server versions prior to 2.19.0, allowing unauthenticated attackers to hijack the 'Restore' functionality via the `/skServer/validateBackup` endpoint. This can lead to account takeover and Remote Code Execution (RCE) by overwriting critical server configuration files. Signal K Server administrators, security teams, and IT personnel responsible for mai [truncated]