Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fpf5-w967-rr2m Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 06 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Signalk signal K Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:*
Vendors & Products Signalk signal K Server

Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Signalk
Signalk signalk-server
Vendors & Products Signalk
Signalk signalk-server

Fri, 02 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Information Disclosure via Exposed Endpoints Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints
References

Thu, 01 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.
Title Unauthenticated Information Disclosure via Exposed Endpoints
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-02T18:56:08.422Z

Reserved: 2025-12-16T14:05:31.364Z

Link: CVE-2025-68273

cve-icon Vulnrichment

Updated: 2026-01-02T18:56:03.313Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-01T19:15:53.630

Modified: 2026-01-06T17:58:57.153

Link: CVE-2025-68273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-05T10:14:46Z

Weaknesses