Back to CVE List

CVE-2026-49955

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Vulnerability Description

Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. Attackers can send unlimited POST requests to the authentication endpoint, causing unbounded growth of the challenge store file and excessive CPU and disk I/O through repeated JSON file rewrites.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-770
Source
NVD
Vendor
nesquena
Product
hermes-webui

External References

Discussion (0)

Add Comment

No comments yet. Be the first!