PT-2026-47853 · Unknown · Hermes-Webui

CVE-2026-49955

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hermes WebUI versions prior to 0.51.270
Description An issue exists where unauthenticated remote attackers can degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. By sending unlimited POST requests to the authentication endpoint, attackers can cause unbounded growth of the challenge store file and excessive CPU and disk I/O due to repeated JSON file rewrites. This leads to resource exhaustion, a state where the system lacks sufficient resources to function properly.
Recommendations Update to version 0.51.270 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49955

Affected Products

Hermes-Webui