Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys. | |
| Title | SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-215 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T11:04:35.278Z
Reserved: 2026-08-16T12:59:42.223Z
Link: CVE-2026-74799
No data.
Status : Received
Published: 2026-08-17T11:16:40.017
Modified: 2026-08-17T11:16:40.017
Link: CVE-2026-74799
No data.
OpenCVE Enrichment
No data.
-
CWE-215
Insertion of Sensitive Information Into Debugging Code