{"api_version":"v1","generated_at":"2026-10-08T09:45:00+00:00","product":{"cve_count":15,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-signalk-signalk-server-d8a618cae7cf","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/signalk-server","name":"signalk-server","next_cursor":null,"observations":[{"affected":"signalk-server: < 2.28.0","affected_versions_present":true,"cve_id":"CVE-2026-55591","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55591","fixed":"2.28.0.","last_modified":"2026-09-15T17:23:51.052Z","patch_url":"https://github.com/SignalK/signalk-server/security/advisories/GHSA-q59x-jc9f-gfqf","primary_source":"","published":"2026-09-15T15:37:55.944Z"},{"affected":"< 2.25.0","affected_versions_present":true,"cve_id":"CVE-2026-41893","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41893","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-14T17:50:55.289Z","patch_url":"https://github.com/SignalK/signalk-server/pull/2568","primary_source":"","published":"2026-05-09T19:12:10.082Z"},{"affected":"< 2.25.0","affected_versions_present":true,"cve_id":"CVE-2026-39320","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39320","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-21T19:36:54.787Z","patch_url":"https://github.com/SignalK/signalk-server/pull/2568","primary_source":"","published":"2026-04-21T00:07:10.371Z"},{"affected":"< 2.24.0","affected_versions_present":true,"cve_id":"CVE-2026-35038","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35038","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T18:46:36.895Z","patch_url":"https://github.com/SignalK/signalk-server/security/advisories/GHSA-qh3j-mrg8-f234","primary_source":"","published":"2026-04-02T16:20:17.750Z"},{"affected":"< 2.24.0","affected_versions_present":true,"cve_id":"CVE-2026-34083","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34083","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T17:39:18.548Z","patch_url":"","primary_source":"","published":"2026-04-02T16:14:38.893Z"},{"affected":"< 2.24.0-beta.1","affected_versions_present":true,"cve_id":"CVE-2026-33951","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33951","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T16:21:53.516Z","patch_url":"","primary_source":"","published":"2026-04-02T16:11:58.762Z"},{"affected":"< 2.24.0-beta.4","affected_versions_present":true,"cve_id":"CVE-2026-33950","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33950","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-03T18:02:34.324Z","patch_url":"","primary_source":"","published":"2026-04-02T16:08:59.415Z"},{"affected":"< 2.20.3","affected_versions_present":true,"cve_id":"CVE-2026-25228","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25228","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-04T21:09:42.637Z","patch_url":"https://github.com/SignalK/signalk-server/commit/9bcf61c8fe2cb8a40998b913a02fb64dff9e86c7","primary_source":"","published":"2026-02-02T23:02:52.062Z"},{"affected":"< 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-23515","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23515","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-03T15:32:04.099Z","patch_url":"https://github.com/SignalK/set-system-time/commit/75b11eae2de528bf89ede3fb1f7ed057ddbb4d24","primary_source":"","published":"2026-02-02T20:43:32.219Z"},{"affected":"signalk-server: < 2.19.0","affected_versions_present":true,"cve_id":"CVE-2025-69203","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-69203","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-02T19:02:25.169Z","patch_url":"","primary_source":"","published":"2026-01-01T18:37:11.015Z"},{"affected":"signalk-server: < 2.19.0","affected_versions_present":true,"cve_id":"CVE-2025-68619","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68619","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-02T19:00:44.776Z","patch_url":"","primary_source":"","published":"2026-01-01T18:35:19.982Z"},{"affected":"signalk-server: < 2.19.0","affected_versions_present":true,"cve_id":"CVE-2025-68620","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68620","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-02T18:58:28.148Z","patch_url":"","primary_source":"","published":"2026-01-01T18:29:35.761Z"},{"affected":"signalk-server: < 2.19.0","affected_versions_present":true,"cve_id":"CVE-2025-68273","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68273","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-02T18:56:08.422Z","patch_url":"","primary_source":"","published":"2026-01-01T18:21:51.678Z"},{"affected":"signalk-server: < 2.19.0","affected_versions_present":true,"cve_id":"CVE-2025-68272","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68272","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-02T18:55:16.709Z","patch_url":"","primary_source":"","published":"2026-01-01T18:08:06.947Z"},{"affected":"signalk-server: < 2.19.0","affected_versions_present":true,"cve_id":"CVE-2025-66398","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66398","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-05T21:00:41.972Z","patch_url":"","primary_source":"","published":"2026-01-01T18:00:38.575Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"SignalK"}}
