
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33203 is an unauthenticated WebSocket denial-of-service vulnerability in SiYuan, a personal knowledge management system developed by b3log. The vulnerability affects all versions up to and including 3.6.1, and was disclosed on March 18, 2026, with a patch released in version 3.6.2. A remote, unauthenticated attacker can exploit an authentication bypass in the WebSocket server to send malformed JSON messages that trigger a Go runtime panic, crashing the kernel process. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, SiYuan Advisory).
The vulnerability has two root causes classified under CWE-248 (Uncaught Exception) and CWE-306 (Missing Authentication for Critical Function). In kernel/server/serve.go, the WebSocket authentication check is bypassed when the request URI contains both /ws?app=siyuan and &id=auth&type=auth — a pattern intended for an authentication page keepalive — allowing unauthenticated connections. Once connected, incoming JSON messages are parsed into a generic map and fields are accessed via unchecked Go type assertions (request["cmd"].(string), request["reqId"].(float64), request["param"].(map[string]interface{})); sending a minimal malformed payload such as {} causes a runtime panic that propagates without local recovery, crashing the kernel process (GitHub Advisory, SiYuan Advisory).
Successful exploitation results in a complete loss of availability for the SiYuan kernel process, as the runtime panic crashes the service. An unauthenticated attacker can repeatedly trigger the crash to cause persistent denial of service, preventing legitimate users from accessing their knowledge base. There is no confidentiality or integrity impact; however, the risk is elevated for deployments exposed beyond localhost, such as Docker containers with port forwarding, reverse proxy setups, LAN-accessible instances, or publicly hosted deployments (GitHub Advisory).
A proof-of-concept exploit is publicly documented in the official security advisory, providing a concrete 6-step reproduction sequence including Docker setup commands, the specific WebSocket URI (ws://127.0.0.1:6806/ws?app=siyuan&id=auth&type=auth), and the minimal malformed payload ({}). No credentials, privileges, or user interaction are required. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.069% (0.00143 raw), placing it in the 21st percentile for exploitation likelihood (SiYuan Advisory, GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog.
http://<target>:6806 in a browser or via curl to verify the SiYuan kernel is running and reachable.ws://<target>:6806/ws?app=siyuan&id=auth&type=auth. The server accepts this connection without credentials due to the keepalive URI pattern match in the authentication logic.{} over the established WebSocket connection. This payload is missing the expected fields (cmd, reqId, param), causing unchecked Go type assertions to fail./ws?app=siyuan&id=auth&type=auth from untrusted or external IP addresses; repeated connection attempts from the same source following service restarts.kernel/server/serve.go during WebSocket message handling; sudden process termination entries in container or system logs (docker logs showing panic output followed by process exit).siyuan binary); container restart events logged by Docker or the container orchestration platform.Upgrade SiYuan to version 3.6.2 or later, which fixes the authentication bypass and adds proper input validation for WebSocket message handling. If immediate patching is not possible, restrict network access to the SiYuan WebSocket server (port 6806) to trusted clients only using firewall rules or network segmentation — particularly ensuring the service is not exposed beyond localhost in Docker or reverse proxy configurations. Avoid using the SIYUAN_ACCESS_AUTH_CODE_BYPASS=true environment variable in production or network-accessible deployments (GitHub Advisory, SiYuan Advisory).
The vulnerability was reported by security researcher mith36 and published by the SiYuan maintainer (88250) on March 18, 2026. An openSUSE security announcement was issued referencing the vulnerability, and it was picked up by Linux security news aggregators. Social media coverage was limited, with a brief mention on Mastodon via @thehackerwire. No significant broader industry commentary or vendor statements beyond the official advisory have been identified (SiYuan Advisory, openSUSE Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."