Impact
SiYuan v3.8.2 and earlier are vulnerable to a denial‑of‑service condition in the unauthenticated /api/system/uiproc endpoint. The endpoint accepts arbitrary process identifiers with no size or authentication limits, allowing an attacker to submit a large number of unique identifiers that consume memory resources. This can lead to memory exhaustion and render the software unavailable to legitimate users.
Affected Systems
The vulnerability affects the Siyuan Note application from the Siyuan vendor, specifically any installation using versions prior to 3.8.2.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and because the endpoint is unauthenticated, a remote attacker can exploit the flaw from any network node with access to the API. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalogue, but the lack of authentication and high impact make it a significant threat for exposed deployments.
OpenCVE Enrichment