hermes-webui vulnerability

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers.

Published 18 Jun 2026Updated 17 Sep 20266 sources
CVSS 6.9

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.