Resource Exhaustion Vulnerability in Hermes WebUI
CVE-2026-49955
6.9MEDIUM
What is CVE-2026-49955?
Hermes WebUI prior to version 0.51.270 is susceptible to a resource exhaustion vulnerability that permits remote, unauthenticated attackers to disrupt service availability. By exploiting this flaw, attackers can repeatedly invoke the passkey options endpoint without completing the necessary assertion, leading to an overwhelming number of POST requests. This results in the challenge store file growing uncontrollably and causes significant strain on CPU and disk I/O due to continuous rewrites of JSON files.
Affected Version(s)
hermes-webui 0
