SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys. | |
| Title | SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-215 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T11:04:35.278Z
Reserved: 2026-08-16T12:59:42.223Z
Link: CVE-2026-74799
No data.
Status : Received
Published: 2026-08-17T11:16:40.017
Modified: 2026-08-17T11:16:40.017
Link: CVE-2026-74799
No data.
OpenCVE Enrichment
Updated: 2026-08-17T12:45:03Z
Weaknesses