SiYuan 在 v3.8.2 之前版本中,发布服务的 Basic Auth 限流机制存在拒绝服务(DoS)漏洞。该机制使用由攻击者控制的、未经验证的用户名来存储认证失败的尝试状态,且未强制执行容量限制或数据淘汰策略。未经身份验证的攻击者可以通过提交带有唯一且无效的用户名的一系列认证请求,从而耗尽内存并增加同步开销,进而降低服务的可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.2 |
affected |
3.8.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85581 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration |
| CVE-2026-85585 | 7.5 HIGH | SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency |
| CVE-2026-85578 | 6.5 MEDIUM | SiYuan through 3.8.1 Authorization Bypass via getFile |
| CVE-2026-85583 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Traversal via symlink in file API |
| CVE-2026-85582 | 6.5 MEDIUM | SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth |
| CVE-2026-85580 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch |
| CVE-2026-85579 | 4.3 MEDIUM | SiYuan before v3.8.2 Information Disclosure via undoState |
No comments yet