{"id":"CVE-2026-55205","title":"Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads","summary":"Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send …","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-770"],"vendor":"nesquena","product":"hermes-webui","affected":["hermes-webui < 0.51.468"],"published":"2026-06-18","updated":"2026-09-17","sourceUpdated":"2026-09-17T18:16:49.510","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55205","references":[{"url":"https://github.com/nesquena/hermes-webui/commit/ce272d9cd5f8e5a4521278f56eb5388010901646","label":"disclosure@vulncheck.com"},{"url":"https://github.com/nesquena/hermes-webui/pull/3970","label":"disclosure@vulncheck.com"},{"url":"https://github.com/nesquena/hermes-webui/pull/4338","label":"disclosure@vulncheck.com"},{"url":"https://github.com/nesquena/hermes-webui/releases/tag/v0.51.468","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hermes-webui-resource-exhaustion-via-unauthenticated-oauth-flow-endpoint","label":"disclosure@vulncheck.com"},{"url":"https://github.com/nesquena/hermes-webui/pull/3970","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-06-18T17:36:03.154710Z"},"epss":0.00366,"epssPercentile":0.30307,"ingestedAt":"2026-09-17T18:25:15.970Z","slug":"CVE-2026-55205","body":"## Overview\n\nHermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}