Beveiligingsadvies

CVE-2026-85581

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-04 11:29:50
Laatst bijgewerkt 2026-09-04 11:29:50
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or authentication. Attackers can send repeated requests with unique identifiers to exhaust process memory and degrade service availability.