PT-2026-50709 · Unknown · Hermes-Webui

CVE-2026-55205

·

Published

2026-06-18

·

Updated

2026-06-19

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hermes WebUI versions prior to 0.51.468
Description An issue exists in the unauthenticated 'POST /api/onboarding/oauth/start' endpoint that allows for unbounded accumulation of in-memory flow state and daemon threads. This can lead to resource exhaustion if an attacker sends repeated or concurrent requests, which may exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers.
Recommendations Update to version 0.51.468 or later. As a temporary workaround, restrict access to the 'POST /api/onboarding/oauth/start' endpoint to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55205

Affected Products

Hermes-Webui