← Terug naar overzicht

SiYuan versions before v3.8.2 contain a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint. The endpoint accepts and retains attacker-controlled process identifiers without enforcing size limits or requiring authentication. Attackers can repeatedly send requests with unique identifiers to exhaust process memory. This leads to degraded service availability and potential full denial of service. The vulnerability requires no authentication, lowering the barrier for exploitation. A fix is available in SiYuan v3.8.2 and later. The issue is tracked as CVE-2026-85581 and has been published via NVD, GitHub Security Advisories, and VulnCheck.

Affected products

  • SiYuan before v3.8.2

Related CVE's

  • CVE-2026-85581

Categories

  • Enterprise Applications
  • Web Technologies