Denial of Service Vulnerability in SiYuan Publishing Platform
CVE-2026-85584
8.7HIGH
What is CVE-2026-85584?
SiYuan versions before v3.8.2 have a denial of service vulnerability related to the Basic Auth throttle in the publish-service. This flaw allows unauthenticated attackers to exploit the system by submitting repeated authentication requests using unique invalid usernames. The system currently lacks capacity limits and eviction policies for tracking failed attempts, which can lead to excessive memory use and significant synchronization overhead, ultimately degrading the availability of the service.
Affected Version(s)
siyuan 0 < 3.8.2
siyuan 3.8.2
