SiYuan 在 v3.8.2 之前存在一个无界资源消耗漏洞,位于请求并发中间件中。该中间件会为每个唯一的请求路径保留互斥锁条目,且没有淘汰机制。未认证的攻击者可以通过发送大量唯一的请求路径,永久性地增加进程内存占用和同步开销,从而降低系统的可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.2 |
affected |
3.8.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85584 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via Auth Throttle |
| CVE-2026-85581 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration |
| CVE-2026-85578 | 6.5 MEDIUM | SiYuan through 3.8.1 Authorization Bypass via getFile |
| CVE-2026-85583 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Traversal via symlink in file API |
| CVE-2026-85582 | 6.5 MEDIUM | SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth |
| CVE-2026-85580 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch |
| CVE-2026-85579 | 4.3 MEDIUM | SiYuan before v3.8.2 Information Disclosure via undoState |
No comments yet