<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 18:43:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-276991</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-276991</link>
      <description>EUVD-2026-276991</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-276991</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33203</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33203</link>
      <description>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts unauthenticated connections when a specific &amp;#34;auth keepalive&amp;#34; query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON. A remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service. Version 3.6.2 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts unauthenticated connections when a specific &amp;#34;auth keepalive&amp;#34; query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON. A remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service. Version 3.6.2 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33203</guid>
    </item>
    <item>
      <title>GHSA-3g9h-9hp4-654v — SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3g9h-9hp4-654v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;## Summary
The SiYuan kernel WebSocket server accepts unauthenticated connections when a specific “auth keepalive” query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON.&lt;/p&gt;
&lt;p&gt;A remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service.&lt;/p&gt;
&lt;p&gt;## Details
**1. Authentication Bypass via Keepalive Query**&lt;/p&gt;
&lt;p&gt;Unauthenticated connections are accepted if the request URI matches a specific pattern intended for an authentication page keepalive.&lt;/p&gt;
&lt;p&gt;**File: kernel/server/serve.go**&lt;/p&gt;
&lt;p&gt;```
if !authOk {
    authOk = strings.Contains(s.Request.RequestURI, &amp;#34;/ws?app=siyuan&amp;#34;) &amp;amp;&amp;amp;
             strings.Contains(s.Request.RequestURI, &amp;#34;&amp;amp;id=auth&amp;amp;type=auth&amp;#34;)
}&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;**2. Unsafe Type Assertions on Untrusted Input**&lt;/p&gt;
&lt;p&gt;Incoming JSON messages are parsed into a generic map and fields are accessed without validation.&lt;/p&gt;
&lt;p&gt;**File: kernel/server/serve.go**&lt;/p&gt;
&lt;p&gt;```
cmdStr := request[&amp;#34;cmd&amp;#34;].(string)
cmdId  := request[&amp;#34;reqId&amp;#34;].(float64)
param  := request[&amp;#34;param&amp;#34;].(map[string]interface{})&lt;/p&gt;
&lt;p&gt;```
Malformed or missing fields trigger a runtime panic.
The handler does not implement local panic recovery, allowing crashes to propagate.&lt;/p&gt;
&lt;p&gt;## PoC
**Step 1 — Prepare workspace directory**&lt;/p&gt;
&lt;p&gt;```sh
mkdir -p ./workspace
```&lt;/p&gt;
&lt;p&gt;**Step 2 — Run SiYuan container**&lt;/p&gt;
&lt;p&gt;```
docker run -d \
  -p 6806:6806 \
  -e SIYUAN_ACCESS_AUTH_CODE_BYPASS=true \
  -v $(pwd)/workspace:/siyuan/workspace \
  b3log…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;## Summary
The SiYuan kernel WebSocket server accepts unauthenticated connections when a specific “auth keepalive” query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON.&lt;/p&gt;
&lt;p&gt;A remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service.&lt;/p&gt;
&lt;p&gt;## Details
**1. Authentication Bypass via Keepalive Query**&lt;/p&gt;
&lt;p&gt;Unauthenticated connections are accepted if the request URI matches a specific pattern intended for an authentication page keepalive.&lt;/p&gt;
&lt;p&gt;**File: kernel/server/serve.go**&lt;/p&gt;
&lt;p&gt;```
if !authOk {
    authOk = strings.Contains(s.Request.RequestURI, &amp;#34;/ws?app=siyuan&amp;#34;) &amp;amp;&amp;amp;
             strings.Contains(s.Request.RequestURI, &amp;#34;&amp;amp;id=auth&amp;amp;type=auth&amp;#34;)
}&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;**2. Unsafe Type Assertions on Untrusted Input**&lt;/p&gt;
&lt;p&gt;Incoming JSON messages are parsed into a generic map and fields are accessed without validation.&lt;/p&gt;
&lt;p&gt;**File: kernel/server/serve.go**&lt;/p&gt;
&lt;p&gt;```
cmdStr := request[&amp;#34;cmd&amp;#34;].(string)
cmdId  := request[&amp;#34;reqId&amp;#34;].(float64)
param  := request[&amp;#34;param&amp;#34;].(map[string]interface{})&lt;/p&gt;
&lt;p&gt;```
Malformed or missing fields trigger a runtime panic.
The handler does not implement local panic recovery, allowing crashes to propagate.&lt;/p&gt;
&lt;p&gt;## PoC
**Step 1 — Prepare workspace directory**&lt;/p&gt;
&lt;p&gt;```sh
mkdir -p ./workspace
```&lt;/p&gt;
&lt;p&gt;**Step 2 — Run SiYuan container**&lt;/p&gt;
&lt;p&gt;```
docker run -d \
  -p 6806:6806 \
  -e SIYUAN_ACCESS_AUTH_CODE_BYPASS=true \
  -v $(pwd)/workspace:/siyuan/workspace \
  b3log…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3g9h-9hp4-654v</guid>
    </item>
  </channel>
</rss>
