FlawAtlas
Search the atlas
CVE-2026-33203 High

SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass in github.com/siyuan-note/siyuan/kernel

SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass in github.com/siyuan-note/siyuan/kernel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/siyuan-note/siyuan/kernel before v3.6.2.

Exploit probability 0.5%
Published March 23, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

675 explicit affected versions

Go github.com/siyuan-note/siyuan/kernel
Go github.com/siyuan-note/siyuan/kernel

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-33203

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts unauthenticated connections when a specific "auth keepalive" query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON. A remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service. Version 3.6.2 fixes the issue.

View original source
Open Source Vulnerabilities GHSA-3g9h-9hp4-654v

## Summary The SiYuan kernel WebSocket server accepts unauthenticated connections when a specific “auth keepalive” query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON. A remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service. ## Details **1. Authentication Bypass via Keepalive Query** Unauthenticated connections are accepted if the request URI matches a specific pattern intended for an authentication page keepalive. **File: kernel/server/serve.go** ``` if !authOk { authOk = strings.Contains(s.Request.RequestURI, "/ws?app=siyuan") && strings.Contains(s.Request.RequestURI, "&id=auth&type=auth") } ``` **2. Unsafe Type Assertions on Untrusted Input** Incoming JSON messages are parsed into a generic map and fields are accessed without validation. **File: kernel/server/serve.go** ``` cmdStr := request["cmd"].(string) cmdId := request["reqId"].(float64) param := request["param"].(map[string]interface{}) ``` Malformed or missing fields trigger a runtime panic. The handler does not implement local panic recovery, allowing crashes to propagate. ## PoC **Step 1 — Prepare workspace directory** ```sh mkdir -p ./workspace ``` **Step 2 — Run SiYuan container** ``` docker run -d \ -p 6806:6806 \ -e SIYUAN_ACCESS_AUTH_CODE_BYPASS=true \ -v $(pwd)/workspace:/siyuan/workspace \ b3log/siyuan \ --workspace=/siyuan/workspace ``` Service becomes reachable at http://127.0.0.1:6806 **Step 3 — Confirm service availability** Open in browser: ```sh http://127.0.0.1:6806 ``` **Step 4 — Connect to unauthenticated WebSocket endpoint** ```sh ws://127.0.0.1:6806/ws?app=siyuan&id=auth&type=auth ``` This connection is accepted without credentials. **Step 5 — Send malformed payload** Payload: ```sh {} ``` **Step 6 — Observe behavior** Monitor container logs: ```sh docker logs -f <container_id> ``` ## Impact An unauthenticated attacker with network access can repeatedly crash the kernel, causing persistent denial of service. Impact is highest when the service is exposed beyond localhost (e.g., Docker deployments, reverse proxies, LAN access, or public hosting).

View original source
Open Source Vulnerabilities GO-2026-4752

SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass in github.com/siyuan-note/siyuan/kernel. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/siyuan-note/siyuan/kernel before v3.6.2.

View original source

05 / REFERENCES

Further evidence