Description
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys. | |
| Title | SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-215 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T11:04:35.278Z
Reserved: 2026-08-16T12:59:42.223Z
Link: CVE-2026-74799
No data.
Status : Received
Published: 2026-08-17T11:16:40.017
Modified: 2026-08-17T11:16:40.017
Link: CVE-2026-74799
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-215
Insertion of Sensitive Information Into Debugging Code