CVE-2026-55591 | SignalK Server up to 2.27.x Remote Request src/serverroutes.ts makeRemoteRequest host/port/useTLS/selfsignedcert server-side request forgery

SecurityVulns

A vulnerability classified as critical has been found in SignalK Server up to 2.27.x. This impacts the function makeRemoteRequest of the file src/serverroutes.ts of the component Remote Request Handler. This manipulation of the argument host/port/useTLS/selfsignedcert causes server-side request forgery.

This vulnerability is tracked as CVE-2026-55591. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More