CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-35038

CVE-2026-35038: Arbitrary Prototype Read in Signal K Server via JSON-Patch Bypass

Alon Barad
Alon Barad
Software Engineer

Apr 3, 2026·7 min read·43 visits

Executive Summary (TL;DR)

An incomplete input validation check in the Signal K Server JSON-patch handler allows authenticated attackers to bypass prototype pollution defenses and read internal server properties via the `from` field.

Signal K Server prior to version 2.24.0 contains an input validation flaw in its JSON-patch endpoint. The application fails to validate the `from` field during copy and move operations, allowing authenticated users to read sensitive properties from the global prototype object.

Vulnerability Overview

Signal K Server acts as a central data hub for marine applications, exposing various API endpoints for data management. The server provides a specific endpoint located at /signalk/v1/applicationData/... that processes JSON-patch operations as defined in RFC 6902. This functionality allows authenticated clients to dynamically modify stored application state through standardized operations.

Prior to version 2.24.0, the JSON-patch implementation contained an asymmetric input validation flaw. The development team implemented a security control, isPrototypePollution, to prevent malicious modification of the global JavaScript prototype object. This control was designed to block payload paths containing restricted keywords such as __proto__, constructor, and prototype.

The vulnerability exists because this validation routine was not applied comprehensively across all JSON-patch operation fields. The destination path field underwent strict validation, successfully mitigating standard prototype pollution attacks. The source from field, utilized specifically in copy and move operations, bypassed this validation routine entirely.

This oversight permits an authenticated user to specify restricted prototype paths as the source of a copy operation. The application then extracts the data from the restricted prototype location and writes it to a user-readable destination path, resulting in an arbitrary prototype read vulnerability.

Root Cause Analysis

The root cause of CVE-2026-35038 is a failure to comprehensively validate all user-controlled path parameters within the JSON-patch processing pipeline. RFC 6902 defines several operations, including add, remove, replace, copy, and move. Operations that transfer data from one location to another, namely copy and move, require both a source location (from) and a destination location (path).

The Signal K Server implementation centralized its prototype pollution defenses around the destination object to prevent attackers from overwriting prototype properties. When processing an operation, the code invoked the isPrototypePollution check exclusively on the path attribute. The code responsible for resolving the source object referenced by the from attribute lacked an equivalent check.

When a client submits a copy operation, the server evaluates the from string to retrieve the target value from memory. Because no boundary checks restrict this resolution process, the server engine traverses the JavaScript prototype chain if instructed to do so via standard prototype identifiers. The server then treats the retrieved internal object or function as standard application data.

The flaw highlights a common anti-pattern in prototype pollution defense where developers focus solely on write operations while neglecting read operations. While arbitrary reads do not corrupt application state, they violate data boundary isolation and expose internal memory structures to unauthorized actors.

Code Analysis and Patch Implementation

The vulnerable code path resides in the JSON-patch processing logic where individual operations are parsed and executed. The implementation relied on a boundary checking function that examined string inputs for banned substrings associated with prototype traversal.

In the vulnerable implementation, the application iterated through the provided JSON-patch array. For each operation, the code verified that op.path did not trigger the isPrototypePollution(op.path) condition. However, operations utilizing the from attribute immediately processed the source path using standard object traversal techniques without passing op.from through the same validation function.

The remediation introduced in version 2.24.0 corrects this asymmetry by applying the isPrototypePollution check to both spatial parameters. The patch logic ensures that any JSON-patch operation containing a from field undergoes identical scrutiny to the path field.

// Vulnerable Logic (Conceptual)
if (isPrototypePollution(operation.path)) {
  throw new Error("Invalid path");
}
// The operation.from field is processed without validation
executePatch(operation.from, operation.path);
 
// Patched Logic (Conceptual)
if (isPrototypePollution(operation.path)) {
  throw new Error("Invalid path");
}
if (operation.from && isPrototypePollution(operation.from)) {
  throw new Error("Invalid from path");
}
executePatch(operation.from, operation.path);

This structural change guarantees that the JSON pointer resolution engine will reject requests attempting to traverse the prototype chain, regardless of whether the traversal occurs during a read phase or a write phase.

Exploitation Methodology

Exploiting this vulnerability requires the attacker to possess valid credentials for the Signal K Server with sufficient privileges to interact with the /signalk/v1/applicationData/... endpoint. The attacker must also identify a valid application data path where they have read access to retrieve the extracted information.

The attack is initiated by constructing a specialized JSON-patch payload using the copy operation. The attacker sets the from field to target the global prototype, using a path such as /constructor/prototype/internalSecretKey. The path field is configured to point to an accessible location within the user's application data namespace, such as /userSettings/myPublicData/leakedValue.

[
  {
    "op": "copy",
    "from": "/constructor/prototype/someInternalSecret",
    "path": "/userSettings/myPublicData/leakedValue"
  }
]

The attacker submits this payload via an HTTP POST or PATCH request to the application data endpoint. The server processes the operation, successfully resolving the restricted source path because the validation filter is bypassed. The server copies the requested internal property and persists it at the user-readable destination.

Following the successful execution of the JSON-patch operation, the attacker issues an HTTP GET request to the destination path. The server returns the contents of the copied prototype property within the JSON response payload, completing the data exfiltration cycle.

Impact Assessment

The vulnerability allows authenticated, low-privileged users to extract internal functions and properties stored on the global JavaScript prototype object. This capability results in unauthorized information disclosure and violates the intended data isolation boundaries of the server environment.

The immediate impact is restricted to data confidentiality. Attackers can map internal application state, extract hidden configuration variables, or retrieve sensitive data structures that developers assumed were inaccessible from the user space. The vulnerability does not permit the modification of prototype properties, preventing direct execution of traditional prototype pollution attacks that lead to remote code execution or denial of service.

The CVSS v4.0 score reflects these constraints with a base score of 2.1 (Low severity). The vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P indicates that the attack is executable over the network with low complexity, requires low privileges, involves no user interaction, and results in a low impact to confidentiality with no impact to integrity or availability.

While the direct impact is limited, the extracted information provides an attacker with deep visibility into the server's execution environment. This internal knowledge reduces the complexity of discovering and exploiting secondary vulnerabilities, making it a valuable reconnaissance primitive during a broader intrusion campaign.

Remediation and Mitigation Guidance

The primary remediation for CVE-2026-35038 is to upgrade Signal K Server to version 2.24.0 or later. This release contains the complete patch that extends input validation to all relevant fields within the JSON-patch processing module. Administrators should schedule a maintenance window to apply this update to all deployed hub systems.

If immediate patching is not feasible due to operational constraints, administrators can implement mitigating controls at the network boundary. A Web Application Firewall (WAF) or reverse proxy can be configured to inspect HTTP request bodies destined for the /signalk/v1/applicationData/... endpoint. The WAF rule should drop any request containing strings like constructor, prototype, or __proto__ within the JSON payload.

Development teams managing similar node-based applications should review their JSON-patch implementations. Security testing must verify that prototype pollution protections apply uniformly to all object traversal mechanisms, including source pointers in read operations. Relying exclusively on destination path validation is insufficient to guarantee data isolation.

Official Patches

SignalKRelease notes for version 2.24.0 containing the fix.

Technical Appendix

CVSS Score
2.1/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Affected Systems

Signal K Server instances running versions prior to 2.24.0

Affected Versions Detail

Product
Affected Versions
Fixed Version
Signal K Server
SignalK
< 2.24.02.24.0
AttributeDetail
CWE IDCWE-20
Attack VectorNetwork
CVSS Score2.1
ImpactLow Confidentiality
Exploit StatusProof of Concept
AuthenticationRequired (Low Privileges)

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
T1552Unsecured Credentials
Credential Access
CWE-20
Improper Input Validation

Improper input validation on JSON-patch source paths allows unauthorized data access.

Known Exploits & Detection

GitHub AdvisoryPrimary advisory detailing the JSON-patch bypass mechanism.

Vulnerability Timeline

Vulnerability referenced in security bulletins.
2026-02-04
Signal K Server version 2.24.0 released containing the patch (Approximate date based on late Jan 2026).
2026-01-30
CVE-2026-35038 published by CVE authorities.
2026-04-02

References & Sources

  • [1]GHSA-qh3j-mrg8-f234 Security Advisory
  • [2]Signal K Server v2.24.0 Release Notes
  • [3]NVD Vulnerability Detail - CVE-2026-35038
  • [4]CVE.org Record - CVE-2026-35038

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•36 minutes ago•CVE-2026-74802
8.2

CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace

CVE-2026-74802 is a critical Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the SiYuan knowledge workspace application. Due to improper origin validation across multiple internal WebSocket endpoints, an attacker can hijack active authenticated sessions when a victim visits an untrusted external page. This allows the attacker to route malicious network traffic through the victim's localized SiYuan server, establishing an authenticated network pivot and facilitating Server-Side Request Forgery (SSRF).

Alon Barad
Alon Barad
2 views•5 min read
•about 2 hours ago•CVE-2026-74904
8.7

CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

A high-severity missing authorization vulnerability (CWE-862) exists in the SiYuan note-taking application before v3.7.4. Seventeen block metadata and content-derived endpoints within kernel/api/block.go lack proper publish-access and role-based checks. This allows low-privilege or anonymous users in publish mode to bypass workspace restrictions and disclose private block content, trace workspace structures, map document indexes, and verify the existence of private notes. The vulnerability is addressed in version v3.7.4.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 3 hours ago•CVE-2026-71416
8.8

CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server

A critical cross-site WebSocket hijacking (CSWSH) vulnerability in headroomlabs-ai/headroom prior to version 0.35.0 allows unauthorized external origins to establish connection channels to the Headroom proxy, enabling arbitrary prompt execution and remote code execution through local tool integration.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 4 hours ago•GHSA-CJCG-CXMH-9WCR
7.5

GHSA-cjcg-cxmh-9wcr: Unbounded Memory Allocation via HTTP/2 Bomb in praxis-proxy

A critical vulnerability exists in the praxis-proxy library where the omission of default limits on HTTP/2 server options allows remote attackers to trigger a Denial of Service (DoS) using an HPACK compression bomb and flow-control window stalls. This vulnerability is cataloged as GHSA-cjcg-cxmh-9wcr.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 5 hours ago•GHSA-MWM8-39RW-8826
8.1

GHSA-MWM8-39RW-8826: Use-After-Free Vulnerability in Ruby sqlite3 Gem native extension

A Use-After-Free (UAF) vulnerability exists in the sqlite3-ruby native C extension when marshaling arguments for user-defined SQLite aggregate functions with multiple arguments. Due to temporary heap-allocated argument arrays not being registered with the Ruby Garbage Collector, active objects can be prematurely reclaimed, resulting in memory corruption or process-level crashes.

Alon Barad
Alon Barad
5 views•7 min read
•about 6 hours ago•CVE-2026-19484
7.5

CVE-2026-19484: Remote Denial of Service via Boyer-Moore-Horspool Integer Wrap-around in @fastify/busboy

An unauthenticated remote denial of service vulnerability exists in @fastify/busboy versions 3.1.0 through 3.2.0. The vulnerability is caused by an integer wrap-around in the Boyer-Moore-Horspool algorithm implementation inside the sbmh submodule when initializing skip distances. When processing a specific boundary of 252 bytes, the parser triggers an infinite loop, stalling the single-threaded Node.js event loop and exhausting CPU resources.

Alon Barad
Alon Barad
6 views•6 min read