Known Vulnerabilities for Hermes by Facebook
Listed below are 10 of the newest known vulnerabilities associated with "Hermes" by "Facebook".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-6832 json | Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated ... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-6830 json | nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environme... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-6829 json | nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a ... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2023-30470 json | A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to c... | 9.8 - CRITICAL | 2023-05-18 | 2023-11-07 |
| CVE-2023-28081 json | A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-... | 9.8 - CRITICAL | 2023-05-18 | 2023-11-07 |
| CVE-2023-25933 json | A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicio... | 9.8 - CRITICAL | 2023-05-18 | 2023-11-07 |
| CVE-2023-24833 json | A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have be... | 7.5 - HIGH | 2023-05-18 | 2023-11-07 |
| CVE-2023-24832 json | A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used by an ... | 7.5 - HIGH | 2023-05-18 | 2023-11-07 |
| CVE-2023-23557 json | An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could b... | 9.8 - CRITICAL | 2023-05-18 | 2023-11-07 |
| CVE-2023-23556 json | An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been us... | 9.8 - CRITICAL | 2023-05-18 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hermes | 2020-10-01 | ||||
| Application | Hermes | 2020-09-25 | ||||
| Application | Hermes | 0.7.2 | ||||
| Application | Hermes | 0.7.1 | ||||
| Application | Hermes | 0.7.0 | ||||
| Application | Hermes | 0.6.0 | ||||
| Application | Hermes | 0.5.3 | ||||
| Application | Hermes | 0.5.2 | ||||
| Application | Hermes | 0.5.1 | ||||
| Application | Hermes | 0.5.0 | ||||
| Application | Hermes | 0.4.4 | ||||
| Application | Hermes | 0.4.3 | ||||
| Application | Hermes | 0.4.1 | ||||
| Application | Hermes | 0.4.0 | ||||
| Application | Hermes | 0.3.0 | ||||
| Application | Hermes | 0.2.1 | ||||
| Application | Hermes | 0.1.1 | ||||
| Application | Hermes | 0.1.0 | ||||
| Application | Hermes | 0.0.3 | ||||
| Application | Hermes | 0.0.2 |