Description
A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Mitigation
AI Analysis

Impact

A flaw in the Session Chat Interface of NousResearch hermes‑agent allows a remote attacker to manipulate the file gateway/platforms/api_server.py module and trigger a denial of service. The vulnerability is identified as a failure to properly manage resources, leading to service unavailability for legitimate users. The impact is that the affected component can be exhausted and must be restarted, interrupting normal operation.

Affected Systems

The vulnerability is known to affect version 0.18.0 of NousResearch hermes‑agent. No other versions are currently listed as impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the issue is not in the CISA KEV catalog. The attack can be carried out remotely, and an exploit has already been published, implying the possibility of real‐world attacks. Because the vendor has not responded to disclosure, there is no official patch or workaround yet available.

Generated by OpenCVE AI on September 2, 2026 at 02:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch for hermes‑agent as soon as it becomes available, even if a public version of the fix is not yet released.
  • Implement input validation or limits on the Session Chat API to prevent malformed requests from exhausting resources.
  • Configure rate limiting or throttling on the Session Chat endpoint to reduce the impact of repeated abuse.
  • Install a perimeter firewall or load balancer rule to detect and block excessive traffic to the api_server.py endpoint.
  • If the service can be temporarily disabled during an attack, do so while investigating a permanent fix.
  • Add monitoring for unusual spikes in session chat traffic and set alert thresholds to detect potential denial‑of‑service activity.

Generated by OpenCVE AI on September 2, 2026 at 02:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title NousResearch hermes-agent Session Chat api_server.py denial of service
First Time appeared Nousresearch
Nousresearch hermes-agent
Weaknesses CWE-404
CPEs cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:*
Vendors & Products Nousresearch
Nousresearch hermes-agent
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Nousresearch Hermes-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-04T02:13:52.318Z

Reserved: 2026-09-01T15:48:32.437Z

Link: CVE-2026-84287

cve-icon Vulnrichment

Updated: 2026-09-04T02:13:47.180Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T21:18:46.567

Modified: 2026-09-04T03:17:43.237

Link: CVE-2026-84287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T03:00:13Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release