CVE-2026-74799
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:L
- EPSS probability
- 0.39%
- CWE
- CWE-215
- Published
- 2026-08-17
- Last modified
- 2026-08-17
Affected products
- siyuan-note siyuan
- siyuan-note siyuan
Weakness type
Related vulnerabilities
- CVE-2026-79694 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-62652 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware...
- CVE-2026-21759 — HCL Hive is affected by an information exposure vulnerability
- CVE-2026-44934 — Exposed tokens in SUSE Rancher AI Agent logs
- CVE-2026-40173 — Dgraph: Unauthenticated pprof endpoint leaks admin auth token
- CVE-2026-33247 — NATS credentials are exposed in monitoring port via command-line argv
- CVE-2026-2250 — Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC
- CVE-2025-12616 — PHPGurukul News Portal settings.py insertion of sensitive information into debugging code