Unrated severityNVD Advisory· Published Jun 18, 2026· Updated Jun 18, 2026
Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint
CVE-2026-55205
Description
Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.51.468
Patches
Vulnerability mechanics
References
5- github.com/nesquena/hermes-webui/commit/ce272d9cd5f8e5a4521278f56eb5388010901646mitrepatch
- www.vulncheck.com/advisories/hermes-webui-resource-exhaustion-via-unauthenticated-oauth-flow-endpointmitrethird-party-advisory
- github.com/nesquena/hermes-webui/pull/3970mitretechnical-description
- github.com/nesquena/hermes-webui/pull/4338mitreissue-tracking
- github.com/nesquena/hermes-webui/releases/tag/v0.51.468mitrerelease-notes
News mentions
0No linked articles in our index yet.