Hermes Agent - Pre-Authentication Memory Exhaustion

Medium

Synopsis

In Hermes Agent the dashboard's public authentication routes (/auth/native/token, /auth/native/refresh, and /auth/password-login) read and parse the entire JSON request body before any authentication check, with no application-level size limit.

The gated_auth_middleware in hermes_cli/dashboard_auth/middleware.py lets these paths through via _GATE_PUBLIC_PREFIXES before checking for a session. The handlers in routes.py rely on Pydantic models whose string fields have no size bound, and the pinned web stack (FastAPI 0.133.1, Starlette 1.3.1, Uvicorn 0.41.0) buffers the full body before the handler runs. Uvicorn's configuration in start_server (hermes_cli/web_server.py) caps WebSocket message size but sets no HTTP body limit.

As a result, an unauthenticated client can send oversized payloads that are fully loaded into memory before being rejected. Testing confirmed that a ~1 MB body to /auth/native/refresh returned 401 instead of 413, and that chunked uploads of 32 MiB and 128 MiB, sent without Content-Length, still reached /auth/password-login's application-level rejection (404). Keeping eight concurrent 32 MiB uploads open for fifteen seconds raised the dashboard process's memory from 721 MiB to 1.08 GiB, while /api/status continued to report overall=ok.

Although every request is ultimately rejected, an anonymous attacker can drive substantial memory consumption by holding several large uploads in progress, which creates a denial-of-service risk.

Solution

Upgrade to Hermes Agent version 0.21.6 or later.

Disclosure Timeline

September 03 2026 - First Contact
September 09 2026 - Second Attempt
September 10 2026 - Nous Research requests details via email or GitHub.
September 10 2026 - Details sent by email
September 16 2026 - Tenable asking for updates
September 23 2026 - Tenable asking for updates
September 29 2026 - Tenable asking for updates
October 05 2026 - Tenable asking for updates
October 05 2026 - Nous Research request to send the details again
October 05 2026 - Tenable has re-sent the reports
October 05 2026 - Fixed on PR #133370

All information within TRA advisories is provided “as is”, without warranty of any kind, including the implied warranties of merchantability and fitness for a particular purpose, and with no guarantee of completeness, accuracy, or timeliness. Individuals and organizations are responsible for assessing the impact of any actual or potential security vulnerability.

Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.

For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.

If you have questions or corrections about this advisory, please email [email protected]