Junglewise Threat Intelligence

CVE-2026-85585: SiYuan unbounded resource consumption in request-concurrency middleware

CVE-2026-85585 · Severity: high · CVSS 7.5 · Published 2026-09-04

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a popular personal knowledge management application. The request-concurrency middleware contains a memory leak that allows unauthenticated attackers to send requests with unique paths to permanently consume server memory and degrade application performance. An attacker can exhaust server resources without authentication or user interaction, causing denial of service.

Technical details

The vulnerability exists in SiYuan's request-concurrency middleware, which maintains a global map of mutex entries keyed by request path (CWE-400: Uncontrolled Resource Consumption). For each unique request path—including non-existent paths that return 404—a new mutex entry is created and retained indefinitely without eviction or size bounds. An unauthenticated attacker can exploit this by sending numerous requests with unique paths (e.g., /api/security-poc-unique-1, /api/security-poc-unique-2, etc.), causing unbounded growth of the in-memory map. The attack vector is network-based with no authentication or user interaction required. This results in memory pressure, increased synchronization overhead, and eventual availability degradation. The vulnerability is fixed in version 3.8.2; versions 3.8.1 and earlier are affected.

Affected products

  • SiYuan SiYuan before 3.8.2

Timeline

  • 2026-08-21: disclosed: GitHub Security Advisory GHSA-p59v-3q54-qq55 published
  • 2026-09-04: patched: Version 3.8.2 released with fix

References

Related threats