CVE-2026-55205: Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint
Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hermes WebUIto a version that resolves this vulnerability.Fixed in 0.51.468
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55205?
CVE-2026-55205 has a medium severity score of 6.9.
How do I fix CVE-2026-55205?
To fix CVE-2026-55205, update Hermes WebUI to version 0.51.468 or later.
What type of attack does CVE-2026-55205 allow?
CVE-2026-55205 allows attackers to conduct resource exhaustion attacks via the unauthenticated OAuth flow endpoint.
What software is affected by CVE-2026-55205?
CVE-2026-55205 affects Hermes WebUI versions prior to 0.51.468.
What is the impact of CVE-2026-55205 on the system?
CVE-2026-55205 can lead to exhaustion of server memory and additional daemon threads, potentially causing service downtime.