cvedb.io
CVE-2026-39320
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-04-21T01:16:05.063 · Last modified 2026-06-17T10:41:54.893

Summary

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (ReDoS) attack within the WebSocket subscription handling logic. By injecting unescaped regex metacharacters into the `context` parameter of a stream subscription, an attacker can force the server's Node.js event loop into a catastrophic backtracking loop when evaluating long string identifiers (like the server's self UUID). This results in a total Denial of Service (DoS) where the server CPU spikes to 100% and becomes completely unresponsive to further API or socket requests. Version 2.25.0 contains a fix.

Affected products

signalk — signal_k_server

Does this affect you?

Add your gear to cvedb and we'll alert you only when signalk ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.