CVE-2026-74799General

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-215

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-17: 1Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 108-1708-18
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-171
General1
2026-08-181
Patch1
Full discourse2 posts
  • iSECTECH@isectech_
    Patch

    SiYuan CVE-2026-74799 can expose unauthenticated pprof data—and in-memory AI API keys—when runtime mode is not exactly prod. Upgrade to 3.7.4, block /debug/pprof/, and rotate keys after exposure. https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9cqq-p2hw-mj3f

    Post summary

    The advisory reports that SiYuan CVE‑2026‑74799 allows unauthenticated access to pprof data and in‑memory AI API keys in non‑prod modes, and it advises users to upgrade to version 3.7.4, block the /debug/pprof/ endpoint, and rotate exposed keys.

    0000032
    86 followersView on X
  • NewNormal Security@NewScanTeam
    General

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 17 Aug 2026 𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan: 🖥️ Go pprof left on a public listener — heap dumps, and the app's own access code, with no login (SiYuan CVE-2026-74799) 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: ⚡ MCP code interpreter escaping its sandbox — RCE on the MCP host from one prompt injection (pptr-mcp CVE-2026-19958, Jij-MCP-Server CVE-2026-19964) 📦 WordPress plugin leaking its stored integration credentials to any URL an anonymous visitor names (WooMS CVE-2026-13700) 𝗔𝗱𝗱𝗲𝗱 𝘁𝗼 𝗡𝗲𝘄𝗦𝗰𝗮𝗻 𝗣𝗿𝗼 — 𝗼𝘂𝘁-𝗼𝗳-𝗯𝗮𝗻𝗱: 🔀 MCP tool fetching a caller-supplied URL — internal services and cloud metadata via the agent's own tool call (facebook-ads-mcp-server CVE-2026-19956, graphlit-mcp-server CVE-2026-19957, mcp-florence2 CVE-2026-19984, PromptShopMCP CVE-2026-74842) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #MCP #CSO #REDTEAM

    Post summary

    NewNormal Security’s daily CVE alert lists several newly covered CVEs with brief impact notes, but contains no PoC, exploit code, patch, or evidence of active exploitation.

    0000067
    5 followersView on X

Explore more