Impact
SiYuan versions before 3.8.2 contain a flaw in the publish-service Basic Auth throttle that records failed authentication attempts using attacker-controlled usernames without imposing limits or eviction policies. By submitting repeated authentication requests with unique, invalid usernames, an attacker can deplete server memory, forcing the application to perform excessive synchronization and causing the service to become unresponsive.
Affected Systems
All installations of SiYuan note software prior to version 3.8.2 are affected, including deployments on Linux, Windows, macOS and mobile platforms that rely on the default publish-service Basic Auth throttle.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating a high severity DoS risk. Exploitation requires no authentication; an attacker only needs the ability to send many authentication requests to the publish service. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment