PT-2026-85485 · Siyuan · Siyuan

·

CVE-2026-85585

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.2
Description The request-concurrency middleware contains an unbounded resource consumption issue where mutex entries are retained for every unique request path without an eviction mechanism. Unauthenticated attackers can exploit this by sending a large number of unique request paths, leading to a permanent increase in process memory and synchronization overhead, which degrades system availability.
Recommendations Update to version 3.8.2 or later.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85585
GHSA-P59V-3Q54-QQ55

Affected Products

Siyuan