PT-2026-50709 · Unknown · Hermes-Webui
CVE-2026-55205
·
Published
2026-06-18
·
Updated
2026-06-19
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI versions prior to 0.51.468
Description
An issue exists in the unauthenticated 'POST /api/onboarding/oauth/start' endpoint that allows for unbounded accumulation of in-memory flow state and daemon threads. This can lead to resource exhaustion if an attacker sends repeated or concurrent requests, which may exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers.
Recommendations
Update to version 0.51.468 or later.
As a temporary workaround, restrict access to the 'POST /api/onboarding/oauth/start' endpoint to minimize the risk of exploitation.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui