Medium severity6.5NVD Advisory· Published Sep 4, 2026
CVE-2026-85582
CVE-2026-85582
Description
SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can repeatedly authenticate with valid credentials to create persistent session entries without expiry or capacity limits, causing indefinite process memory growth and denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.8.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.