Sceawere

Vulnerability Detail

CVE-2026-84287UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hermes-Agent Remote Denial Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
NousResearch
Product
hermes-agent
Attack Type
Denial of Service
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-01T21:18:46.567Z",
  "pubdate": "2026-09-01T21:18:46.567Z",
  "executiveSummary": "A critical security vulnerability has been identified in the Session Chat Interface of the NousResearch hermes-agent, specifically affecting version 0.18.0.\nThe flaw resides within the file gateway/platforms/api_server.py and allows for a remote Denial of Service (DoS) attack.\nThis vulnerability poses a significant risk to service availability, as an attacker can trigger a crash or resource exhaustion remotely without requiring authentication.\nThe absence of vendor response following early disclosure increases the risk, as no official patches are currently available to remediate this issue.\nGiven that proof-of-concept exploit code has been publicly released, the likelihood of exploitation is high, necessitating immediate defensive measures to secure affected deployments.",
  "technicalDetails": "The vulnerability is situated in the gateway/platforms/api_server.py component of the NousResearch hermes-agent 0.18.0, which acts as a bridge for the Session Chat Interface.\nThe root cause is an improper handling of input or state management within the api_server.py logic, which, when subjected to specifically crafted network requests, leads to an unhandled exception or resource exhaustion.\nBecause this component operates as a network-facing API server, the attack surface is exposed remotely via standard communication protocols utilized by the agent.\nThe exploitation process involves an attacker transmitting a malicious payload to the endpoint defined within the vulnerable file. Upon receiving the payload, the application enters an unstable state—likely due to a memory leak, process deadlock, or a critical unhandled exception—which terminates the service process or renders it incapable of responding to further legitimate requests.\nThis vulnerability is particularly concerning because it does not require authentication or elevated privileges to execute; the attacker only needs network reachability to the API server component.\nThe post-exploitation impact is a total loss of availability for the Session Chat Interface. As the service is designed for real-time interaction, the resulting DoS disrupts dependent workflows and potentially impacts broader system stability if the agent's failure triggers downstream errors in integrated components.\nGiven that the exploit is public, the attack flow is straightforward: 1. Network reconnaissance to identify the target port running the hermes-agent API; 2. Transmission of the malicious payload targeting the undocumented or vulnerable functionality in api_server.py; 3. Observed crash or resource saturation of the host service, resulting in service interruption.\nThe lack of vendor intervention means that the vulnerability remains unpatched in the 0.18.0 release, leaving deployments inherently susceptible to this specific attack vector."
}
CVE-2026-84287: Hermes-Agent Remote Denial Service (MEDIUM Severity, CVSS: 4.3) - Sceawere