CVE-2026-55205 Details
Description
Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers.
A resource exhaustion vulnerability has been identified in Hermes WebUI versions prior to 0.51.468. The issue resides in the unauthenticated POST /api/onboarding/oauth/start endpoint, where it allows unlimited accumulation of in-memory flow states and daemon threads. Attackers can exploit this by sending repeated or concurrent requests, draining server memory and thread resources. This exploitation could lead to excessive outbound device-code requests to upstream OAuth providers.
Users can update to Hermes WebUI version 0.51.468 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nesquena/hermes-webui/pull/3970 | CISA-ADP | Source CodeVendor |
| https://github.com/nesquena/hermes-webui/commit/ce272d9cd5f8e5a4521278f56eb5388010901646 | [email protected] | Source CodeVendor |
| https://github.com/nesquena/hermes-webui/pull/3970 | [email protected] | Source CodeVendor |
| https://github.com/nesquena/hermes-webui/pull/4338 | [email protected] | Source CodeVendor |
| https://github.com/nesquena/hermes-webui/releases/tag/v0.51.468 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/hermes-webui-resource-exhaustion-via-unauthenticated-oauth-flow-endpoint | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Hermes WebUI | < 0.51.468 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |
Volerion