Skip to main content

CVE-2026-55591: CWE-918: Server-Side Request Forgery (SSRF) in SignalK signalk-server

0
Medium
VulnerabilityCVE-2026-55591cvecve-2026-55591cwe-918
Published: 09/15/2026 (09/15/2026, 15:37:55 UTC)
Source: CVE Database V5
Vendor/Project: SignalK
Product: signalk-server

Description

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalKConnection, requestAccess, and checkAccessRequest endpoints without validating the destination. When security was not configured, addAdminMiddleware() was a no-op in dummysecurity.ts, leaving all three endpoints accessible without authentication. The server could be forced to contact loopback, private, link-local, cloud metadata, or arbitrary external destinations, and selfsignedcert could disable certificate verification for outbound HTTPS requests. The checkAccessRequest endpoint also interpolated requestId into its destination path, allowing traversal to other paths on the selected host. Distinct success, connection-refused, and timeout responses enabled internal port scanning; returned response bodies enabled cloud metadata and internal-service data exfiltration; requestAccess enabled server-side POST requests with attacker-controlled JSON; and access to cluster-internal services could support lateral movement. This issue is fixed in version 2.28.0.

CVSS v3.1

Score 5.8medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected software

SignalK

signalk-server

Affected versions
<2.28.0
GitHub Actionsmore threats →ai
signalk/signalk-server
pkg:github/signalk/signalk-server
Affected versions
<2.28.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/15/2026, 16:02:08 UTC

Technical Analysis

SignalK signalk-server versions before 2.28.0 contain an SSRF vulnerability (CWE-918) due to insufficient validation of host, port, useTLS, and selfsignedcert parameters in the makeRemoteRequest() function. When security is disabled, the addAdminMiddleware() function is a no-op, leaving the testSignalKConnection, requestAccess, and checkAccessRequest endpoints accessible without authentication. This allows attackers to coerce the server into making arbitrary network requests, including to loopback, private, link-local, cloud metadata, or external hosts. The vulnerability also enables internal port scanning via distinct response behaviors, exfiltration of internal service data, and execution of server-side POST requests with attacker-controlled JSON. The checkAccessRequest endpoint's interpolation of requestId into the destination path allows path traversal on the target host. These combined factors can facilitate reconnaissance, data leakage, and lateral movement within the affected environment. The vulnerability is resolved in version 2.28.0.

Potential Impact

An attacker can exploit this SSRF vulnerability to make the signalk-server initiate network requests to arbitrary internal or external destinations, potentially bypassing security controls. This can lead to internal port scanning, exfiltration of sensitive data from cloud metadata and internal services, and unauthorized POST requests with attacker-controlled payloads. The vulnerability also enables path traversal on the destination host, increasing the risk of data exposure. These impacts can facilitate further attacks such as lateral movement within a cluster or environment. The CVSS 3.1 base score is 5.8 (medium severity), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and partial confidentiality impact.

Mitigation Recommendations

This vulnerability is fixed in SignalK signalk-server version 2.28.0. Users should upgrade to version 2.28.0 or later to remediate this issue. Until the upgrade is applied, configuring security to enable authentication and validation on the affected endpoints can reduce exposure. Patch status is confirmed fixed in 2.28.0.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-16T23:18:03.170Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aa9688d55bf5e2cf5074e5b

Added to database: 09/15/2026, 15:47:25 UTC

Last enriched: 09/15/2026, 16:02:08 UTC

Last updated: 09/16/2026, 02:14:33 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses