Description
Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalKConnection, requestAccess, and checkAccessRequest endpoints without validating the destination. When security was not configured, addAdminMiddleware() was a no-op in dummysecurity.ts, leaving all three endpoints accessible without authentication. The server could be forced to contact loopback, private, link-local, cloud metadata, or arbitrary external destinations, and selfsignedcert could disable certificate verification for outbound HTTPS requests. The checkAccessRequest endpoint also interpolated requestId into its destination path, allowing traversal to other paths on the selected host. Distinct success, connection-refused, and timeout responses enabled internal port scanning; returned response bodies enabled cloud metadata and internal-service data exfiltration; requestAccess enabled server-side POST requests with attacker-controlled JSON; and access to cluster-internal services could support lateral movement. This issue is fixed in version 2.28.0.
Published: 2026-09-15
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery enabling internal network exposure and lateral movement
Action: Apply Patch
AI Analysis

Impact

Signal K Server, a server application running on a central hub aboard a boat, contained a Server‑Side Request Forgery flaw before version 2.28.0. In that version, the makeRemoteRequest() function accepted attacker‑controlled host, port, useTLS, and selfsignedcert values from the testSignalKConnection, requestAccess, and checkAccessRequest endpoints without validating the destination. When a security configuration was not present, addAdminMiddleware() performed no authentication, thereby exposing these endpoints freely. An attacker could force the server to reach loopback, private, link‑local, cloud metadata, or arbitrary external endpoints, including disabling certificate verification for outbound HTTPS requests via selfsignedcert. The checkAccessRequest endpoint also interpolated requestId into the destination path, allowing traversal to other paths on the chosen host. Distinct success, connection‑refused, and timeout responses enabled internal port scanning; the returned body content permitted cloud‑metadata and internal‑service data exfiltration; requestAccess enabled arbitrary server‑side POST requests with attacker‑controlled JSON, and access to cluster‑internal services could facilitate lateral movement. This issue is fixed in the 2.28.0 release.

Affected Systems

The vulnerability applies to Signal K Server (SignalK:signalk-server) versions prior to 2.28.0. Any deployment running these older image tags is susceptible.

Risk and Exploitability

The CVSS score of 5.8 indicates a moderate impact and the EPSS score of <1% suggests a low exploitation probability; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation of the publicly exposed testSignalKConnection, requestAccess, and checkAccessRequest endpoints. Successful exploitation requires no additional privileges, as the security middleware is absent; the attacker can perform internal port scanning, metadata theft, and lateral movement within the ship’s network. The risk is elevated for installations lacking authentication and those exposing the vulnerable endpoints to the internet.

Generated by OpenCVE AI on September 20, 2026 at 16:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Signal K Server to version 2.28.0 or newer, which removes the invalid input handling and adds proper authentication checks for the affected endpoints.
  • Configure the server’s security settings so that addAdminMiddleware enforces authentication, ensuring that only authorized users can access testSignalKConnection, requestAccess, and checkAccessRequest.
  • Restrict or disable the testSignalKConnection, requestAccess, and checkAccessRequest endpoints in a production environment, or place them behind strict firewall rules or VPN access to prevent unauthenticated interaction.

Generated by OpenCVE AI on September 20, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-q59x-jc9f-gfqf Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Signalk
Signalk signalk-server
Vendors & Products Signalk
Signalk signalk-server

Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalKConnection, requestAccess, and checkAccessRequest endpoints without validating the destination. When security was not configured, addAdminMiddleware() was a no-op in dummysecurity.ts, leaving all three endpoints accessible without authentication. The server could be forced to contact loopback, private, link-local, cloud metadata, or arbitrary external destinations, and selfsignedcert could disable certificate verification for outbound HTTPS requests. The checkAccessRequest endpoint also interpolated requestId into its destination path, allowing traversal to other paths on the selected host. Distinct success, connection-refused, and timeout responses enabled internal port scanning; returned response bodies enabled cloud metadata and internal-service data exfiltration; requestAccess enabled server-side POST requests with attacker-controlled JSON; and access to cluster-internal services could support lateral movement. This issue is fixed in version 2.28.0.
Title Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Signalk Signalk-server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T17:23:51.052Z

Reserved: 2026-06-16T23:18:03.170Z

Link: CVE-2026-55591

cve-icon Vulnrichment

Updated: 2026-09-15T17:23:47.053Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:14.703

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)