SiYuan 在 v3.8.2 之前的版本中存在一个无限制的会话创建漏洞,位于 publish-service 的基础认证(Basic Auth)处理器中。该漏洞允许已认证的攻击者通过反复使用有效凭证进行认证,从而创建持久化的会话条目,且这些会话既无过期时间也无容量限制。这种机制会导致进程内存无限制地增长,最终引发内存耗尽,造成服务拒绝(DoS)攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.2 |
affected |
3.8.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85584 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via Auth Throttle |
| CVE-2026-85581 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration |
| CVE-2026-85585 | 7.5 HIGH | SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency |
| CVE-2026-85578 | 6.5 MEDIUM | SiYuan through 3.8.1 Authorization Bypass via getFile |
| CVE-2026-85583 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Traversal via symlink in file API |
| CVE-2026-85580 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch |
| CVE-2026-85579 | 4.3 MEDIUM | SiYuan before v3.8.2 Information Disclosure via undoState |
No comments yet