pkg:npm/signalk-server
共 13 筆 CVECRITICAL3HIGH4MEDIUM4
✅ 檢查你的版本
所有已知漏洞
- CRITICAL9.6CVE-2025-66398Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)from 0, < 2.19.0
- CRITICAL9.4CVE-2026-33950Signal K Server: Privilege Escalation by Admin Role Injection via /enableSecurityfrom 0, < 2.24.0-beta.4
- CRITICAL9.1CVE-2025-68620Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Pollingfrom 0, < 2.19.0
- HIGH7.5CVE-2026-39320Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Pathsfrom 0, < 2.25.0
- from 0, < 2.24.0-beta.1
- HIGH7.5CVE-2025-68272Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Floodingfrom 0, < 2.19.0
- from 0, < 2.9.0
- from 0, < 2.19.0
- MEDIUM6.1CVE-2026-34083Signal K Server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC Flow>= 2.20.0, < 2.24.0
- MEDIUM5.3CVE-2025-68273Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpointsfrom 0, < 2.19.0
- from 0, < 2.20.3
- —CVE-2026-41893Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)from 0, < 2.25.0
- from 0, < 2.24.0