CVE-2026-55205

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources, potentially triggering repeated outbound device-code requests to upstream OAuth providers.
Configurations

No configuration.

History

18 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-18 17:16

Updated : 2026-06-22 18:43


NVD link : CVE-2026-55205

Mitre link : CVE-2026-55205

CVE.ORG link : CVE-2026-55205


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling