CVE-2026-84289 Overview
CVE-2026-84289 is an uncontrolled memory allocation vulnerability affecting NousResearch hermes-agent versions up to 0.18.2. The flaw resides in the list_tools function within tools/mcp_tool.py, part of the Model Context Protocol (MCP) Tool component. An authenticated remote attacker can trigger the vulnerability to exhaust process memory, resulting in a denial-of-service condition. The weakness is classified under [CWE-400: Uncontrolled Resource Consumption]. Public exploit details have been released, and according to the disclosure the vendor did not respond to notification attempts.
Critical Impact
Remote attackers with low-privilege access can trigger uncontrolled memory allocation in the list_tools function, degrading availability of the hermes-agent MCP service.
Affected Products
- NousResearch hermes-agent versions up to and including 0.18.2
- Component: MCP Tool (tools/mcp_tool.py)
- Function: list_tools
Discovery Timeline
- 2026-09-01 - CVE-2026-84289 published to the National Vulnerability Database
- 2026-09-02 - Last updated in NVD database
Technical Details for CVE-2026-84289
Vulnerability Analysis
The vulnerability affects the list_tools function inside tools/mcp_tool.py, which handles tool enumeration requests from MCP clients. The function processes untrusted input and allocates memory without enforcing upper bounds, allowing a caller to influence allocation size. Repeated or crafted requests amplify resource consumption on the host running the agent. Because the attack requires only low-level privileges and network reachability, an authenticated user of the MCP interface can degrade service for all consumers. The public technical report describes this pattern as a resource-amplification denial-of-service against the Hermes MCP Tool.
Root Cause
The root cause is missing validation and rate limiting on data structures returned or processed by list_tools. Under [CWE-400], the code path allocates memory proportional to attacker-controlled input without bounding total consumption. There is no ceiling on the number of tool objects instantiated per request, and no back-pressure mechanism throttles concurrent callers. See the GitHub DoS Report for reproduction details.
Attack Vector
Exploitation occurs over the network against an exposed hermes-agent MCP endpoint. An attacker authenticates with low privileges, then issues repeated or oversized list_tools invocations to force the Python process to allocate memory until the operating system terminates it or the host swaps to disk. No user interaction is required. Refer to the VulDB entry for CVE-2026-84289 for the disclosed exploit metadata.
Detection Methods for CVE-2026-84289
Indicators of Compromise
- Rapid memory growth in the Python process hosting hermes-agent, followed by OOM-kill events in system logs.
- Elevated request rates to the MCP list_tools endpoint from a single authenticated principal.
- Repeated agent restarts or unresponsive MCP sessions correlated with client bursts.
Detection Strategies
- Instrument the MCP server with per-endpoint metrics that track request count, response size, and allocation duration for list_tools.
- Alert on anomalous ratios between request payload size and server-side memory allocation.
- Correlate authentication logs with process memory telemetry to identify the initiating account.
Monitoring Recommendations
- Ingest hermes-agent application logs and host-level memory metrics into a centralized analytics pipeline for baselining.
- Configure thresholds on resident set size (RSS) for the agent process and trigger alerts on sustained growth.
- Retain MCP audit logs long enough to reconstruct the sequence of list_tools calls preceding any outage.
How to Mitigate CVE-2026-84289
Immediate Actions Required
- Restrict network exposure of the hermes-agent MCP endpoint to trusted clients only, using firewall rules or a reverse proxy with authentication.
- Enforce per-user rate limits and connection quotas in front of the MCP interface until a patched release is available.
- Monitor the agent process for abnormal memory consumption and configure automatic restart policies with alerting.
Patch Information
At the time of publication, no vendor patch is referenced in the advisory. According to the disclosure summary on VulDB, the maintainer was contacted but did not respond. Track the upstream NousResearch hermes-agent repository for a fixed release beyond version 0.18.2 and apply it when published.
Workarounds
- Deploy a reverse proxy that enforces request size limits, concurrency caps, and rate limiting on list_tools calls.
- Run the agent under a Linux cgroup or container with a hard memory limit to contain the impact of exhaustion.
- Disable or gate the MCP Tool component if list_tools functionality is not required in the deployment.
# Example: constrain hermes-agent memory via systemd
# /etc/systemd/system/hermes-agent.service.d/override.conf
[Service]
MemoryMax=1G
MemoryHigh=768M
TasksMax=256
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
