
🔴 fast-jwt, Expiration Bypass Vulnerability, #CVE-2026-35038 (Critical) -DC-Oct2026-2989 https://dailycve.com/fast-jwt-expiration-bypass-vulnerability-cve-2026-35038-critical-dc-oct2026-2989/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal functions and properties from the global prototype object this violates data isolation and lets a user read more than they should. This issue has been patched in version 2.24.0.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

🔴 fast-jwt, Expiration Bypass Vulnerability, #CVE-2026-35038 (Critical) -DC-Oct2026-2989 https://dailycve.com/fast-jwt-expiration-bypass-vulnerability-cve-2026-35038-critical-dc-oct2026-2989/
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | signalk | signal_k_server | - | - | - |