← Terug naar overzicht

SiYuan versions before v3.8.2 contain a denial of service vulnerability in the publish-service Basic Auth throttle mechanism. The flaw arises from storing failed authentication attempt state using attacker-controlled usernames without enforcing any capacity limits or eviction policies. Unauthenticated attackers can exploit this by submitting repeated authentication requests with unique invalid usernames, causing unbounded memory growth. This exhausts available memory and increases synchronization overhead, ultimately degrading service availability. The vulnerability requires no authentication to exploit, lowering the barrier for abuse. It has been assigned CVE-2026-85584 and is documented in both the NVD and GitHub Security Advisories. A fix was introduced in SiYuan v3.8.2. Users are advised to upgrade to the patched version immediately.

Affected products

  • SiYuan before v3.8.2

Related CVE's

  • CVE-2026-85584

Categories

  • Enterprise Applications
  • Web Technologies