Junglewise Threat Intelligence

CVE-2026-84287: NousResearch hermes-agent denial of service in session chat

CVE-2026-84287 · Severity: medium · CVSS 4.3 · Published 2026-09-01

Technologies: NousResearch Hermes Agent. Vendors: NousResearch.

Executive brief

NousResearch hermes-agent is an AI agent library used for building conversational applications. A flaw in the Session Chat Interface component allows remote attackers to cause a denial of service, disrupting availability of applications built on this library without requiring authentication.

Technical details

A denial of service vulnerability exists in hermes-agent 0.18.0 within the Session Chat Interface component, specifically in the gateway/platforms/api_server.py file. The vulnerability is remotely exploitable without authentication. An attacker can leverage this flaw to trigger a denial of service condition, impacting application availability. A public exploit is available, and the vendor did not respond to early disclosure attempts.

Affected products

  • NousResearch hermes-agent 0.18.0

Timeline

  • 2026-09-01: disclosed

References

Related threats