CVE-2026-33203: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33203 is an unauthenticated WebSocket denial-of-service vulnerability in SiYuan, a personal knowledge management system developed by b3log. The vulnerability affects all versions up to and including 3.6.1, and was disclosed on March 18, 2026, with a patch released in version 3.6.2. A remote, unauthenticated attacker can exploit an authentication bypass in the WebSocket server to send malformed JSON messages that trigger a Go runtime panic, crashing the kernel process. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, SiYuan Advisory).

Technical details

The vulnerability has two root causes classified under CWE-248 (Uncaught Exception) and CWE-306 (Missing Authentication for Critical Function). In kernel/server/serve.go, the WebSocket authentication check is bypassed when the request URI contains both /ws?app=siyuan and &id=auth&type=auth — a pattern intended for an authentication page keepalive — allowing unauthenticated connections. Once connected, incoming JSON messages are parsed into a generic map and fields are accessed via unchecked Go type assertions (request["cmd"].(string), request["reqId"].(float64), request["param"].(map[string]interface{})); sending a minimal malformed payload such as {} causes a runtime panic that propagates without local recovery, crashing the kernel process (GitHub Advisory, SiYuan Advisory).

Impact

Successful exploitation results in a complete loss of availability for the SiYuan kernel process, as the runtime panic crashes the service. An unauthenticated attacker can repeatedly trigger the crash to cause persistent denial of service, preventing legitimate users from accessing their knowledge base. There is no confidentiality or integrity impact; however, the risk is elevated for deployments exposed beyond localhost, such as Docker containers with port forwarding, reverse proxy setups, LAN-accessible instances, or publicly hosted deployments (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the official security advisory, providing a concrete 6-step reproduction sequence including Docker setup commands, the specific WebSocket URI (ws://127.0.0.1:6806/ws?app=siyuan&id=auth&type=auth), and the minimal malformed payload ({}). No credentials, privileges, or user interaction are required. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.069% (0.00143 raw), placing it in the 21st percentile for exploitation likelihood (SiYuan Advisory, GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or LAN-accessible SiYuan instances running versions ≤ 3.6.1, particularly Docker deployments with port 6806 exposed. Tools like Shodan or Censys can be used to locate publicly accessible instances.
  2. Confirm service availability: Access http://<target>:6806 in a browser or via curl to verify the SiYuan kernel is running and reachable.
  3. Connect to the unauthenticated WebSocket endpoint: Establish a WebSocket connection to ws://<target>:6806/ws?app=siyuan&id=auth&type=auth. The server accepts this connection without credentials due to the keepalive URI pattern match in the authentication logic.
  4. Send malformed JSON payload: Transmit a minimal malformed JSON message such as {} over the established WebSocket connection. This payload is missing the expected fields (cmd, reqId, param), causing unchecked Go type assertions to fail.
  5. Trigger runtime panic: The failed type assertions raise an unrecovered Go runtime panic in the WebSocket message handler, crashing the SiYuan kernel process.
  6. Repeat for persistent DoS: Re-send the malformed payload after any automatic restart to maintain a persistent denial-of-service condition (SiYuan Advisory).

Indicators of compromise

  • Network: Unexpected WebSocket connection attempts to port 6806 with the URI pattern /ws?app=siyuan&id=auth&type=auth from untrusted or external IP addresses; repeated connection attempts from the same source following service restarts.
  • Logs: SiYuan kernel logs showing Go runtime panic stack traces originating from kernel/server/serve.go during WebSocket message handling; sudden process termination entries in container or system logs (docker logs showing panic output followed by process exit).
  • Process: Unexpected termination and restart of the SiYuan kernel process (siyuan binary); container restart events logged by Docker or the container orchestration platform.
  • Application: SiYuan service becoming intermittently or persistently unavailable on port 6806 without a clear administrative cause (SiYuan Advisory).

Mitigation and workarounds

Upgrade SiYuan to version 3.6.2 or later, which fixes the authentication bypass and adds proper input validation for WebSocket message handling. If immediate patching is not possible, restrict network access to the SiYuan WebSocket server (port 6806) to trusted clients only using firewall rules or network segmentation — particularly ensuring the service is not exposed beyond localhost in Docker or reverse proxy configurations. Avoid using the SIYUAN_ACCESS_AUTH_CODE_BYPASS=true environment variable in production or network-accessible deployments (GitHub Advisory, SiYuan Advisory).

Community reactions

The vulnerability was reported by security researcher mith36 and published by the SiYuan maintainer (88250) on March 18, 2026. An openSUSE security announcement was issued referencing the vulnerability, and it was picked up by Linux security news aggregators. Social media coverage was limited, with a brief mention on Mastodon via @thehackerwire. No significant broader industry commentary or vendor statements beyond the official advisory have been identified (SiYuan Advisory, openSUSE Announce).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management