Impact
The vulnerability allows an attacker to cause unbounded memory consumption by sending a large number of unique request paths to the request-concurrency middleware. Because the middleware retains a mutex entry for each unique path without eviction, memory usage grows indefinitely, eventually exhausting system resources and degrading availability.
Affected Systems
The affected product is SiYuan, a note‑taking application from Siyuan Note (vendor: siyuan-note:siyuan). All releases before version 3.8.2 are vulnerable. The advisory lists versions up to 3.8.1.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, but EPSS is not available, so the likelihood of exploitation in the wild cannot be quantified. The vulnerability is not listed in CISA KEV. The attack is carried out by unauthenticated attackers through normal HTTP requests, exploiting the request‑concurrency middleware.
OpenCVE Enrichment