Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. Attackers can send unlimited POST requests to the authentication endpoint, causing unbounded growth of the challenge store file and excessive CPU and disk I/O through repeated JSON file rewrites.
History

Tue, 09 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Description Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. Attackers can send unlimited POST requests to the authentication endpoint, causing unbounded growth of the challenge store file and excessive CPU and disk I/O through repeated JSON file rewrites.
Title Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-09T16:05:33.140Z

Reserved: 2026-06-02T16:30:15.232Z

Link: CVE-2026-49955

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-09T17:17:48.770

Modified: 2026-06-09T17:17:48.770

Link: CVE-2026-49955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.