Resource Exhaustion Vulnerability in Hermes WebUI
CVE-2026-49955

6.9MEDIUM

Key Information:

Vendor

Nesquena

Vendor
CVE Published:
9 June 2026

What is CVE-2026-49955?

Hermes WebUI prior to version 0.51.270 is susceptible to a resource exhaustion vulnerability that permits remote, unauthenticated attackers to disrupt service availability. By exploiting this flaw, attackers can repeatedly invoke the passkey options endpoint without completing the necessary assertion, leading to an overwhelming number of POST requests. This results in the challenge store file growing uncontrollably and causes significant strain on CPU and disk I/O due to continuous rewrites of JSON files.

Affected Version(s)

hermes-webui 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.