PT-2026-47853 · Unknown · Hermes-Webui
CVE-2026-49955
·
Published
2026-06-09
·
Updated
2026-06-09
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI versions prior to 0.51.270
Description
An issue exists where unauthenticated remote attackers can degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. By sending unlimited POST requests to the authentication endpoint, attackers can cause unbounded growth of the challenge store file and excessive CPU and disk I/O due to repeated JSON file rewrites. This leads to resource exhaustion, a state where the system lacks sufficient resources to function properly.
Recommendations
Update to version 0.51.270 or later.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui