Signalk is a modestly represented but prominent maritime data-integration platform centered on its Signal K Server, which aggregates and distributes vessel sensor and navigation data across marine networks. Its vulnerability profile skews toward serious outcomes, with an elevated share of disclosures reaching critical severity, while the recurring weakness classes—including authentication bypass, sensitive information exposure, OS command injection, and resource-exhaustion flaws—reflect the open-network and command-execution risks inherent to a broadly accessible server component in safety-critical maritime environments. Defenders operating marine systems should treat this vendor's advisories as high-priority given the operational impact potential; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Signalk over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66398HIGH Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath` | Jan 1, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-33950CRITICAL Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection | Apr 2, 2026 | 9.4 | 32 | NO | NO |
CVE-2026-23515HIGH Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to | Feb 2, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-68620CRITICAL Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication | Jan 1, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-41893HIGH Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are pr | May 9, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-69203HIGH Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by | Jan 1, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-39320HIGH Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (Re | Apr 21, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-68272HIGH Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker | Jan 1, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-68619HIGH Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages throug | Jan 1, 2026 | 7.2 | 25 | NO | NO |
CVE-2026-35038MEDIUM Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. T | Apr 2, 2026 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Signalk.
Media articles that mention a CVE ID that affects a product developed by Signalk — matched by CVE ID, not by vendor name.