CVE-2026-49955: Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. Attackers can send unlimited POST requests to the authentication endpoint, causing unbounded growth of the challenge store file and excessive CPU and disk I/O through repeated JSON file rewrites.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hermes WebUIto a version that resolves this vulnerability.Fixed in 0.51.270
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49955?
The severity of CVE-2026-49955 is rated as medium with a score of 5.3.
How do I fix CVE-2026-49955?
To fix CVE-2026-49955, update Hermes WebUI to version 0.51.270 or later.
What type of vulnerability is CVE-2026-49955?
CVE-2026-49955 is a resource exhaustion vulnerability.
Who is affected by CVE-2026-49955?
Unauthenticated remote attackers can exploit CVE-2026-49955 to degrade service availability.
What impact does CVE-2026-49955 have?
CVE-2026-49955 can lead to service degradation by allowing repeated calls to the passkey options endpoint.