---
id: CVE-2026-85585
title: >-
  SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability
  in the request-concurrency middleware that retains mutex entries for every
  unique request path without eviction
summary: >-
  SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability
  in the request-concurrency middleware that retains mutex entries for every
  unique request path without eviction. Unauthenticated attackers can send
  numerous un…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:05:53.177'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85585'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-p59v-3q54-qq55
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-3.8.2-unbounded-memory-consumption-via-controlconcurrency
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-p59v-3q54-qq55
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00367
epssPercentile: 0.30461
ingestedAt: '2026-09-08T20:10:03.164Z'
---

## Overview

SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated attackers can send numerous unique request paths to permanently increase process memory and synchronization overhead, degrading availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
