MediumVulnerability
Hermes Agent - Pre-Authentication Memory Exhaustion
- Published
- Record updated
Summary
Hermes Agent's dashboard authentication routes, /auth/native/token, /auth/native/refresh and /auth/password-login, read and parse the full JSON request body before any authentication check, with no application-level size limit. An anonymous client can hold several large uploads open to drive dashboard memory up, which the source reports rising from 721 MiB to 1.08 GiB during testing, creating a denial-of-service risk.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database
- HighCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of serviceSimilar attack · NVD/CVE Database