<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T00:50:31.830423+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318564</id>
    <title>EUVD-2026-318564</title>
    <updated>2026-10-06T00:50:31.883562+00:00</updated>
    <content>EUVD-2026-318564</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41893</id>
    <title>fkie_cve-2026-41893</title>
    <updated>2026-10-06T00:50:31.883614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-rate-limit (default: 100 attempts per 10-minute window, configurable via HTTP_RATE_LIMITS). The WebSocket login path — sending {login: {username, password}} messages over an established WebSocket connection — calls app.securityStrategy.login() directly without any rate limiting. An attacker can bypass HTTP rate limiting entirely by opening a WebSocket connection and attempting unlimited password guesses at the speed bcrypt allows (~20 attempts/sec with 10 salt rounds). This issue has been patched in version 2.25.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vmfm-ch9h-5c7g</id>
    <title>GHSA-vmfm-ch9h-5c7g — Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)</title>
    <updated>2026-10-06T00:50:31.883654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: signalk-server</p>
<p>## Summary</p>
<p>The HTTP login endpoints (`POST /login` and `POST /signalk/v1/auth/login`) are protected by `express-rate-limit` (default: 100 attempts per 10-minute window, configurable via `HTTP_RATE_LIMITS`). The WebSocket login path — sending `{login: {username, password}}` messages over an established WebSocket connection — calls `app.securityStrategy.login()` directly without any rate limiting.</p>
<p>An attacker can bypass HTTP rate limiting entirely by opening a WebSocket connection and attempting unlimited password guesses at the speed bcrypt allows (~20 attempts/sec with 10 salt rounds).</p>
<p>## Details</p>
<p>**Vulnerable code:** `src/interfaces/ws.ts`, function `processLoginRequest` (lines 753-780)</p>
<p>The function directly calls `app.securityStrategy.login(msg.login.username, msg.login.password)` with no throttling or attempt tracking.</p>
<p>**Rate-limited HTTP path for comparison:** `src/tokensecurity.ts` lines 609-617 apply `loginLimiter` middleware to the HTTP login routes at line 637.</p>
<p>## Steps to Reproduce</p>
<p>1. Start Signal K server with security enabled
2. Open a WebSocket connection to `ws://server:3000/signalk/v1/stream?subscribe=none`
3. Wait for the hello message
4. Send login attempts in rapid succession:
   ```json
   {"requestId": "1", "login": {"username": "admin", "password": "guess1"}}
   {"requestId": "2", "login": {"username": "admin", "password": "guess2"}}
   ```
5. Observe that all attempts are processed without any 429 response or throttling
6. For comparison, send 100…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vmfm-ch9h-5c7g"/>
  </entry>
</feed>
