top of page
perceptive_background_267k.jpg

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression D…

Published:

20 april 2026 om 22:00:00

Alert date:

21 april 2026 om 17:05:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Web Technologies

Signal K Server versions prior to 2.25.0 contain an unauthenticated Regular Expression Denial of Service (ReDoS) vulnerability in WebSocket subscription handling logic. Attackers can inject unescaped regex metacharacters into the context parameter of stream subscriptions, causing catastrophic backtracking loops in the Node.js event loop. This results in complete server denial of service with 100% CPU usage and total unresponsiveness to API or socket requests. The vulnerability affects the server's self UUID evaluation process. Version 2.25.0 contains a fix for this critical issue.

Technical details

Mitigation steps:

Affected products:

Signal K Server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page