{"api_version":"1","generated_at":"2026-06-01T17:07:40+00:00","cve":"CVE-2026-10224","urls":{"html":"https://cve.report/CVE-2026-10224","api":"https://cve.report/api/cve/CVE-2026-10224.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-10224","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-10224"},"summary":{"title":"NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption","description":"A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","state":"PUBLISHED","assigner":"VulDB","published_at":"2026-06-01 06:16:38","updated_at":"2026-06-01 15:15:37"},"problem_types":["CWE-400","CWE-404","CWE-400 Resource Consumption","CWE-404 Denial of Service"],"metrics":[{"version":"4.0","source":"cna@vuldb.com","type":"Secondary","score":"5.5","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"DECLARED","score":"6.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","data":{"baseScore":6.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","version":"4.0"}},{"version":"3.1","source":"cna@vuldb.com","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R","data":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R","version":"3.1"}},{"version":"3.0","source":"CNA","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R","data":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R","version":"3.0"}},{"version":"2.0","source":"cna@vuldb.com","type":"Secondary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}},{"version":"2.0","source":"CNA","type":"DECLARED","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR","data":{"baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR","version":"2.0"}}],"references":[{"url":"https://gist.github.com/YLChen-007/0304e313d811f187ade93d3b01de0f87","name":"https://gist.github.com/YLChen-007/0304e313d811f187ade93d3b01de0f87","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/submit/822022","name":"https://vuldb.com/submit/822022","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/367503/cti","name":"https://vuldb.com/vuln/367503/cti","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/cve/CVE-2026-10224","name":"https://vuldb.com/cve/CVE-2026-10224","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://vuldb.com/vuln/367503","name":"https://vuldb.com/vuln/367503","refsource":"cna@vuldb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-10224","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10224","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.0","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.1","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.2","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.3","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.4","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.5","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.6","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.7","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.8","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.9","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.10","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.11","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.12","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.13","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.14","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.15","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.16","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.17","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.18","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.19","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.20","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.21","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.22","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.23","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.24","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.25","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.26","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.27","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.28","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.29","platforms":[]},{"source":"CNA","vendor":"NousResearch","product":"hermes-agent","version":"affected 2026.4.30","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-05-31T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"source":"CNA","time":"2026-05-31T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"source":"CNA","time":"2026-05-31T09:56:48.000Z","lang":"en","value":"VulDB entry last update"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Eric-j (VulDB User)","lang":"en"},{"source":"CNA","value":"VulDB CNA Team","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:*"],"modules":["Webhook Endpoint"],"product":"hermes-agent","vendor":"NousResearch","versions":[{"status":"affected","version":"2026.4.0"},{"status":"affected","version":"2026.4.1"},{"status":"affected","version":"2026.4.2"},{"status":"affected","version":"2026.4.3"},{"status":"affected","version":"2026.4.4"},{"status":"affected","version":"2026.4.5"},{"status":"affected","version":"2026.4.6"},{"status":"affected","version":"2026.4.7"},{"status":"affected","version":"2026.4.8"},{"status":"affected","version":"2026.4.9"},{"status":"affected","version":"2026.4.10"},{"status":"affected","version":"2026.4.11"},{"status":"affected","version":"2026.4.12"},{"status":"affected","version":"2026.4.13"},{"status":"affected","version":"2026.4.14"},{"status":"affected","version":"2026.4.15"},{"status":"affected","version":"2026.4.16"},{"status":"affected","version":"2026.4.17"},{"status":"affected","version":"2026.4.18"},{"status":"affected","version":"2026.4.19"},{"status":"affected","version":"2026.4.20"},{"status":"affected","version":"2026.4.21"},{"status":"affected","version":"2026.4.22"},{"status":"affected","version":"2026.4.23"},{"status":"affected","version":"2026.4.24"},{"status":"affected","version":"2026.4.25"},{"status":"affected","version":"2026.4.26"},{"status":"affected","version":"2026.4.27"},{"status":"affected","version":"2026.4.28"},{"status":"affected","version":"2026.4.29"},{"status":"affected","version":"2026.4.30"}]}],"credits":[{"lang":"en","type":"reporter","value":"Eric-j (VulDB User)"},{"lang":"en","type":"coordinator","value":"VulDB CNA Team"}],"descriptions":[{"lang":"en","value":"A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}],"metrics":[{"cvssV4_0":{"baseScore":6.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","version":"4.0"}},{"cvssV3_1":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R","version":"3.1"}},{"cvssV3_0":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R","version":"3.0"}},{"cvssV2_0":{"baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR","version":"2.0"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-400","description":"Resource Consumption","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-404","description":"Denial of Service","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-01T04:30:08.987Z","orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB"},"references":[{"name":"VDB-367503 | NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption","tags":["vdb-entry","technical-description"],"url":"https://vuldb.com/vuln/367503"},{"name":"VDB-367503 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"],"url":"https://vuldb.com/vuln/367503/cti"},{"name":"CVE-2026-10224 | CVE Analysis and Report","tags":["third-party-advisory"],"url":"https://vuldb.com/cve/CVE-2026-10224"},{"name":"Submit #822022 | NousResearch hermes-agent <= v2026.4.30 Uncontrolled Resource Consumption (CWE-400)","tags":["third-party-advisory"],"url":"https://vuldb.com/submit/822022"},{"tags":["exploit"],"url":"https://gist.github.com/YLChen-007/0304e313d811f187ade93d3b01de0f87"}],"timeline":[{"lang":"en","time":"2026-05-31T00:00:00.000Z","value":"Advisory disclosed"},{"lang":"en","time":"2026-05-31T02:00:00.000Z","value":"VulDB entry created"},{"lang":"en","time":"2026-05-31T09:56:48.000Z","value":"VulDB entry last update"}],"title":"NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption"}},"cveMetadata":{"assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","assignerShortName":"VulDB","cveId":"CVE-2026-10224","datePublished":"2026-06-01T04:30:08.987Z","dateReserved":"2026-05-31T07:51:32.069Z","dateUpdated":"2026-06-01T04:30:08.987Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-01 06:16:38","lastModifiedDate":"2026-06-01 15:15:37","problem_types":["CWE-400","CWE-404","CWE-400 Resource Consumption","CWE-404 Denial of Service"],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"10224","Ordinal":"1","Title":"NousResearch hermes-agent Webhook Endpoint feishu.py _handle_web","CVE":"CVE-2026-10224","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"10224","Ordinal":"1","NoteData":"A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","Type":"Description","Title":"NousResearch hermes-agent Webhook Endpoint feishu.py _handle_web"}]}}}