CVE-2025-68272

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "JavaScript heap out of memory" error due to unbounded in-memory storage of request objects. Version 2.19.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-01 18:15

Updated : 2026-01-06 18:23


NVD link : CVE-2025-68272

Mitre link : CVE-2025-68272

CVE.ORG link : CVE-2025-68272


JSON object : View

Products Affected

signalk

  • signal_k_server
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling