CVE-2026-84287
Received Received - Intake

Denial of Service in NousResearch Hermes Agent

Vulnerability report for CVE-2026-84287, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: VulDB

Description

A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nousresearch hermes-agent 0.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service flaw in NousResearch hermes-agent 0.18.0. It affects the Session Chat Interface component in the file gateway/platforms/api_server.py. An attacker can remotely exploit this issue to cause the service to become unavailable.

Detection Guidance

Detection methods for this vulnerability are not specified in the provided CVE details. The flaw involves a denial of service in the Session Chat Interface of NousResearch hermes-agent 0.18.0. Manual inspection of the file gateway/platforms/api_server.py is recommended.

Impact Analysis

If you use NousResearch hermes-agent 0.18.0, an attacker could disrupt the Session Chat Interface, making it unavailable for legitimate users. This could lead to service outages and loss of functionality for chat-based interactions.

Compliance Impact

This vulnerability causes a denial of service in the Session Chat Interface of NousResearch hermes-agent 0.18.0, which could disrupt availability of services. While not directly impacting data confidentiality or integrity, prolonged downtime may affect compliance with regulations like GDPR or HIPAA that require timely access to personal or health data.

Mitigation Strategies

Immediately update or patch the NousResearch hermes-agent to the latest version. If no patch is available, disable the affected Session Chat Interface component in gateway/platforms/api_server.py to prevent remote exploitation. Monitor network traffic for unusual activity targeting this interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84287. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart