Skip to content
HighVulnerability

Hermes Agent - Pre-Authentication Disk Consumption

Published
Record updated
View JSON

Summary

Hermes Agent's public POST /auth/password-login route copies the client-supplied provider value into the audit log without any size limit, before rejecting an unknown provider. Because the route is treated as public, an unauthenticated client can cause arbitrarily large, attacker-controlled data to be written persistently to disk. Testing showed a 100 MiB request reduced free disk space from 919 MB to 819 MB, and repeated requests could exhaust disk space and degrade availability.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.